CVE Tools

Extensis

8 CVEs tracked since 2020. Since Jan 2020, none of them reached CISA KEV.

Extensis CVEs per month

Jan 2020 to Mar 2022. Point at a month, or focus the strip and use the arrow keys.
Extensis CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-0130
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-0350

Products

The products that kept showing up in Extensis's monthly top three, with their CVEs summed over those months.

  1. Portfolio51 month
  2. Mrsid31 month

Latest CVEs

The 10 most recently published vulnerabilities affecting Extensis.

  1. CVE-2022-24255Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.8.8
  2. CVE-2022-24254An unrestricted file upload vulnerability in the Backup/Restore Archive component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted ZIP file.8.8
  3. CVE-2022-24253Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the component AdminFileTransferServlet.8.8
  4. CVE-2022-24252An unrestricted file upload vulnerability in the FileTransferServlet component of Extensis Portfolio v4.0 allows remote attackers to execute arbitrary code via a crafted file.8.8
  5. CVE-2022-24251Extensis Portfolio v4.0 was discovered to contain an authenticated unrestricted file upload vulnerability via the Catalog Asset Upload function.8.8
  6. CVE-2013-3944Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via an IMAGE tag.7.8
  7. CVE-2013-3945The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.7.8
  8. CVE-2013-3946Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a levels header.7.8
  9. CVE-2017-18006netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.6.1
  10. CVE-2005-4510Directory traversal vulnerability in server.np in NetPublish Server 7 allows remote attackers to read arbitrary files via "../" sequences in the template parameter.5.0

The record

Peak rank
#116 in Mar 2022
Busiest month shown
Mar 2022, 5 CVEs
Months with a KEV entry
0 since Jan 2020
Monthly snapshots
2 since 2020
Extensis's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store