Vector's vulnerability profile centers on a narrow set of infrastructure and management products, including the Ultra Mini HTTPd web server and Outage Manager utility, that occupy specialized deployment contexts. The durable signal across its disclosures is rooted in memory-safety weaknesses, specifically improper restrictions on buffer operations, which recur as the primary attack surface for these components. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vector over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-5019HIGH Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP request. | Jul 31, 2013 | 10.0 | 77 | NO | YES |
CVE-2014-6754MEDIUM The Vector Outage Manager (aka nz.co.vector.outagemanager) application 1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers | Sep 28, 2014 | 5.4 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vector.
Media articles that mention a CVE ID that affects a product developed by Vector — matched by CVE ID, not by vendor name.