CVE Tools

SOFT3304

8 CVEs tracked since 2005. Since Feb 2005, none of them reached CISA KEV.

SOFT3304 CVEs per month

Feb 2005 to Aug 2006. Point at a month, or focus the strip and use the arrow keys.
SOFT3304 CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0230
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-0850

Products

The products that kept showing up in SOFT3304's monthly top three, with their CVEs summed over those months.

  1. 04webserver82 months

Latest CVEs

The 9 most recently published vulnerabilities affecting SOFT3304.

  1. CVE-2004-2662Soft3304 04WebServer before 1.41 allows remote attackers to cause a denial of service (resource consumption or crash) via certain data related to OpenSSL, which causes a thread to terminate but con...5.0
  2. CVE-2004-2661Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code).5.0
  3. CVE-2002-2216Soft3304 04WebServer before 1.20 does not properly process URL strings, which allows remote attackers to obtain unspecified sensitive information.5.0
  4. CVE-2006-4199Cross-site scripting (XSS) vulnerability in Soft3304 04WebServer 1.83 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before ...6.8
  5. CVE-2006-4200Unspecified vulnerability in 04WebServer 1.83 and earlier allows remote attackers to bypass user authentication via unspecified vectors related to request processing.7.5
  6. CVE-2005-1416Directory traversal vulnerability in 04WebServer 1.81 allows remote attackers to read files outside of the web root but within the installation folder.5.0
  7. CVE-2004-151304WebServer 1.42 does not adequately filter data that is written to log files, which could allow remote attackers to inject carriage return characters into the log file and spoof log entries.5.0
  8. CVE-2004-1512Cross-site scripting (XSS) vulnerability in Response_default.html in 04WebServer 1.42 allows remote attackers to execute arbitrary web script or HTML via script code in the URL, which is not quoted...4.3
  9. CVE-2004-151404WebServer 1.42 allows remote attackers to cause a denial of service (fail to restart properly) via an HTTP request for an MS-DOS device name such as COM2.5.0

The record

Peak rank
#18 in Aug 2006
Busiest month shown
Aug 2006, 5 CVEs
Months with a KEV entry
0 since Feb 2005
Monthly snapshots
2 since 2005
SOFT3304's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store