Surfcontrol's vulnerability profile centers on web and email filtering appliances designed for enterprise content control and security policy enforcement. The recurring disclosures affecting its SuperScout product line frequently acquire public exploit code, reflecting the appeal of gateway filtering systems as targets for bypass research and access escalation. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Surfcontrol over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0709HIGH SQL injection vulnerabilities in the Web Reports Server for SurfControl SuperScout WebFilter allow remote attackers to execute arbitrary SQL queries via the RunReport option to Sim | Oct 10, 2002 | 7.5 | 28 | NO | YES |
CVE-2002-0708MEDIUM Directory traversal vulnerability in the Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to read arbitrary files via an HTTP request containing ... | Oct 10, 2002 | 5.0 | 25 | NO | YES |
CVE-2002-1530MEDIUM The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp progr | Mar 31, 2003 | 5.0 | 24 | NO | YES |
CVE-2002-1529MEDIUM Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert a | Mar 31, 2003 | 4.3 | 22 | NO | YES |
CVE-2002-0705HIGH The Web Reports Server for SurfControl SuperScout WebFilter stores the "scwebusers" username and password file in a web-accessible directory, which allows remote attackers to obtai | Oct 10, 2002 | 7.5 | 20 | NO | NO |
CVE-2002-2121MEDIUM SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or (2) RCPT TO command, possibly due to a b | Dec 31, 2002 | 5.0 | 19 | NO | NO |
CVE-2002-0706HIGH UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the adminis | Oct 10, 2002 | 7.5 | 19 | NO | NO |
CVE-2002-1531MEDIUM The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Conte | Mar 31, 2003 | 5.0 | 15 | NO | NO |
CVE-2002-1532MEDIUM The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request wit | Mar 31, 2003 | 5.0 | 15 | NO | NO |
CVE-2002-0707MEDIUM The Web Reports Server for SurfControl SuperScout WebFilter allows remote attackers to cause a denial of service (CPU consumption) via large GET requests, possibly due to a buffer | Oct 10, 2002 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Surfcontrol.
Media articles that mention a CVE ID that affects a product developed by Surfcontrol — matched by CVE ID, not by vendor name.