ViewCVS is a web-based repository browser for CVS and Subversion version-control systems, providing read-only access to source-code histories and changeset metadata. The observed vulnerability exposure centers on the application's role as a publicly accessible web interface to code repositories, where input-handling and access-control weaknesses can pose risks to the integrity and confidentiality of tracked source code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Viewcvs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0771MEDIUM Cross-site scripting vulnerability in viewcvs.cgi for ViewCVS 0.9.2 allows remote attackers to inject script and steal cookies via the (1) cvsroot or (2) sortby parameters. | Aug 12, 2002 | 6.4 | 28 | NO | YES |
CVE-2005-4830HIGH CRLF injection vulnerability in viewcvs in ViewCVS 0.9.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in | Dec 31, 2005 | 7.6 | 20 | NO | NO |
CVE-2004-0915MEDIUM Multiple unknown vulnerabilities in viewcvs before 0.9.2, when exporting a repository as a tar archive, does not properly implement the hide_cvsroot and forbidden settings, which c | Jan 10, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-4831MEDIUM viewcvs in ViewCVS 0.9.2 allows remote attackers to set the Content-Type header to arbitrary values via the content-type parameter, which can be leveraged for cross-site scripting | Dec 31, 2005 | 4.3 | 14 | NO | NO |
CVE-2004-1062MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in ViewCVS 0.9.2 allow remote attackers to inject arbitrary HTML and web script via certain error messages. | Dec 28, 2004 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Viewcvs.
Media articles that mention a CVE ID that affects a product developed by Viewcvs — matched by CVE ID, not by vendor name.