Home/Product/github enterprise server
Product

github enterprise server

157 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-8106
>= 3.19.1 and < 3.19.6
A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could a
6.1MEDIUM
CVE-2026-8034
< 3.16.18
A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an
9.8CRITICAL
CVE-2026-7541
< 3.16.18
A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause ser
7.5HIGH
CVE-2026-6736
< 3.16.18
An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to crea
6.5MEDIUM
CVE-2026-5921
< 3.14.26
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to extract
8.9HIGH
CVE-2026-5845
< 3.14.26
An improper authorization vulnerability in scoped user-to-server (ghu_) token authorization in GitHub Enterprise Server allows an
9.6CRITICAL
CVE-2026-5512
< 3.14.26
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to deter
4.3MEDIUM
CVE-2026-4821
< 3.14.26
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an authentica
7.2HIGH
CVE-2026-4296
< 3.14.26
An incorrect regular expression vulnerability was identified in GitHub Enterprise Server that allowed an attacker to bypass OAuth
8.8HIGH
CVE-2026-3307
< 3.14.26
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one
2.7LOW
CVE-2026-3582
< 3.16.15
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with a clas
4.3MEDIUM
CVE-2026-2266
< 3.18.6
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed DOM-based cross-site scr
5.4MEDIUM
CVE-2026-3854
< 3.14.24
An improper neutralization of special elements vulnerability was identified in GitHub Enterprise Server that allowed an attacker w
8.8HIGH
CVE-2026-3306
< 3.14.24
An improper authorization vulnerability was identified in GitHub Enterprise Server that allowed a user with read access to a repos
4.3MEDIUM
CVE-2026-1999
< 3.17.11
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to merge their own pu
6.5MEDIUM
CVE-2026-1355
< 3.14.23
A Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to upload unauthorized c
6.5MEDIUM
CVE-2026-0573
< 3.14.22
An URL redirection vulnerability was identified in GitHub Enterprise Server that allowed attacker-controlled redirects to leak sen
9.0CRITICAL
CVE-2025-13744
>= 3.14.0 and < 3.14.20
An Improper Neutralization of Input During Web Page Generation vulnerability was identified in GitHub Enterprise Server that allow
5.4MEDIUM
CVE-2025-14046
< 3.14.21
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed user-supplied HTML to in
6.1MEDIUM
CVE-2025-11892
< 3.14.19
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross-site scri
9.6CRITICAL
CVE-2025-11578
>= 3.14.0 and < 3.14.20
A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise admin to
7.2HIGH
CVE-2025-8447
< 3.14.17
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed users with access to any reposito
3.1LOW
CVE-2025-6981
< 3.14.5
An incorrect authorization vulnerability allowed unauthorized read access to the contents of internal repositories for contractor
4.3MEDIUM
CVE-2025-6600
>= 3.17.0 and < 3.17.2
An exposure of sensitive information vulnerability was identified in GitHub Enterprise Server that could allow an attacker to disc
4.3MEDIUM
CVE-2025-3509
< 3.13.16
A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary
7.2HIGH
CVE-2025-3246
all versions
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in
7.6HIGH
CVE-2025-3124
< 3.13.14
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private r
4.3MEDIUM
CVE-2024-10001
< 3.11.6
A Code Injection vulnerability was identified in GitHub Enterprise Server that allowed attackers to inject malicious code into the
7.1HIGH
CVE-2025-23369
< 3.12.14
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed signatur
8.8HIGH
CVE-2024-8810
>= 3.10.0 and < 3.10.17
A GitHub App installed in organizations could upgrade some permissions from read to write access without approval from an organiza
6.5MEDIUM
CVE-2024-10824
>= 3.13.0 and < 3.13.2
An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed unauthorized internal users to acces
6.5MEDIUM
CVE-2024-10007
< 3.11.17
A path collision and arbitrary code execution vulnerability was identified in GitHub Enterprise Server that allowed container esca
9.1CRITICAL
CVE-2024-9539
< 3.11.16
An information disclosure vulnerability was identified in GitHub Enterprise Server via attacker uploaded asset URL allowing the at
4.3MEDIUM
CVE-2024-9487
< 3.11.16
An improper verification of cryptographic signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO
9.1CRITICAL
CVE-2024-8770
>= 3.10.0 and < 3.10.17
A Cross-Site Scripting (XSS) vulnerability was identified in the repository transfer feature of GitHub Enterprise Server, which al
6.1MEDIUM
CVE-2024-8263
>= 3.10.0 and < 3.10.17
An improper privilege management vulnerability allowed arbitrary workflows to be committed using an improperly scoped PAT through
2.7LOW
CVE-2024-7711
>= 3.11.0 and < 3.11.14
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an attacker to update the title, ass
4.3MEDIUM
CVE-2024-6800
>= 3.10.0 and < 3.10.16
An XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specifi
9.8CRITICAL
CVE-2024-6337
>= 3.10.0 and < 3.10.16
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a GitHub App with only content: r
6.5MEDIUM
CVE-2024-6395
>= 3.9.0 and < 3.9.17
An exposure of sensitive information vulnerability in GitHub Enterprise Server would allow an attacker to enumerate the names of p
5.3MEDIUM
CVE-2024-6336
>= 3.9.0 and < 3.9.17
A Security Misconfiguration vulnerability in GitHub Enterprise Server allowed sensitive information disclosure to unauthorized use
5.3MEDIUM
CVE-2024-5817
>= 3.9.0 and < 3.9.17
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed read access to issue content via
6.5MEDIUM
CVE-2024-5816
>= 3.9.0 and < 3.9.17
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed a suspended GitHub App to retain
5.3MEDIUM
CVE-2024-5815
>= 3.9.0 and < 3.9.17
A Cross-Site Request Forgery vulnerability in GitHub Enterprise Server allowed write operations on a victim-owned repository by ex
6.5MEDIUM
CVE-2024-5795
>= 3.9.0 and < 3.9.17
A Denial of Service vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause unbounded resource
7.7HIGH
CVE-2024-5566
>= 3.9.0 and < 3.9.17
An improper privilege management vulnerability allowed users to migrate private repositories without having appropriate scopes def
5.8MEDIUM
CVE-2024-5746
< 3.9.16
A Server-Side Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with the Site Admi
7.6HIGH
CVE-2024-4985
< 3.9.15
An authentication bypass vulnerability was present in the GitHub Enterprise Server (GHES) when utilizing SAML single sign-on authe
9.8CRITICAL
CVE-2024-2440
< 3.9.13
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on a detached repository by making
5.5MEDIUM
CVE-2024-3684
< 3.9.13
A server side request forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor rol
8.0HIGH
CVE-2024-3646
< 3.9.13
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the M
8.0HIGH
CVE-2024-3470
>= 3.11.0 and < 3.11.8
An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use a deploy
5.9MEDIUM
CVE-2024-1908
< 3.8.16
An Improper Privilege Management vulnerability was identified in GitHub Enterprise Server that allowed an attacker to use the Ent
6.3MEDIUM
CVE-2024-2748
all versions
A Cross Site Request Forgery vulnerability was identified in GitHub Enterprise Server that allowed an attacker to execute unauthor
4.3MEDIUM
CVE-2024-2469
< 3.8.17
An attacker with an Administrator role in GitHub Enterprise Server could gain SSH root access via remote code execution. This vul
8.0HIGH
CVE-2024-2443
< 3.8.17
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the M
9.1CRITICAL
CVE-2024-1482
>= 3.8.0 and < 3.9.10
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed an attacker to create new branche
7.1HIGH
CVE-2024-1378
< 3.8.15
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the M
9.1CRITICAL
CVE-2024-1374
< 3.8.15
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the M
9.1CRITICAL
CVE-2024-1372
< 3.8.15
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the M
9.1CRITICAL
CVE-2024-1369
< 3.8.15
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the M
9.1CRITICAL
CVE-2024-1359
< 3.8.15
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the M
9.1CRITICAL
CVE-2024-1355
< 3.8.15
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the M
9.1CRITICAL
CVE-2024-1354
< 3.8.15
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the M
8.0HIGH
CVE-2024-1084
< 3.8.15
Cross-site Scripting in the tag name pattern field in the tag protections UI in GitHub Enterprise Server allows a malicious websi
6.5MEDIUM
CVE-2024-1082
< 3.8.15
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker to gain unauthorized read perm
6.3MEDIUM
CVE-2024-0507
< 3.8.13
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command inje
6.5MEDIUM
CVE-2024-0200
>= 3.8.0 and < 3.8.13
An unsafe reflection vulnerability was identified in GitHub Enterprise Server that could lead to reflection injection. This vulner
7.2HIGH
CVE-2023-6847
>= 3.9.0 and < 3.9.7
An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed a bypass of Private Mode by using
7.5HIGH
CVE-2023-6804
>= 3.8.0 and < 3.8.12
Improper privilege management allowed arbitrary workflows to be committed and run using an improperly scoped PAT. To exploit this,
6.5MEDIUM
CVE-2023-6803
>= 3.8.0 and < 3.8.12
A race condition in GitHub Enterprise Server allows an outside collaborator to be added while a repository is being transferred. T
5.8MEDIUM
CVE-2023-6802
>= 3.8.0 and < 3.8.12
An insertion of sensitive information into the log file in the audit log in GitHub Enterprise Server was identified that could al
7.2HIGH
CVE-2023-6746
>= 3.7.0 and < 3.7.19
An insertion of sensitive information into log file vulnerability was identified in the log files for a GitHub Enterprise Server b
8.1HIGH
CVE-2023-6690
>= 3.8.0 and < 3.8.12
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on transferred repositories by maki
3.9LOW
CVE-2023-51380
>= 3.7.0 and < 3.7.19
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be read with an
2.7LOW
CVE-2023-51379
>= 3.7.0 and < 3.7.19
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed issue comments to be updated with
4.9MEDIUM
CVE-2023-46649
>= 3.7.0 and < 3.7.19
A race condition in GitHub Enterprise Server was identified that could allow an attacker administrator access. To exploit this, an
6.3MEDIUM
CVE-2023-46648
>= 3.8.0 and < 3.8.12
An insufficient entropy vulnerability was identified in GitHub Enterprise Server (GHES) that allowed an attacker to brute force a
8.3HIGH
CVE-2023-46647
>= 3.8.0 and < 3.8.12
Improper privilege management in all versions of GitHub Enterprise Server allows users with authorized access to the management co
8.0HIGH
CVE-2023-46646
>= 3.7.0 and < 3.7.19
Improper access control in all versions of GitHub Enterprise Server allows unauthorized users to view private repository names via
5.3MEDIUM
CVE-2023-46645
>= 3.7.0 and < 3.7.19
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitH
6.8MEDIUM
CVE-2023-23766
< 3.6.17
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an in
4.5MEDIUM
CVE-2023-4501
all versions
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, En
9.8CRITICAL
CVE-2023-23763
>= 3.6.0 and < 3.6.18
An authorization/sensitive information disclosure vulnerability was identified in GitHub Enterprise Server that allowed a fork to
5.3MEDIUM
CVE-2023-23765
>= 3.6.0 and < 3.6.16
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an in
4.8MEDIUM
CVE-2023-23764
>= 3.7.0 and < 3.7.9
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an in
4.8MEDIUM
CVE-2023-32265
all versions
A potential security vulnerability has been identified in the Enterprise Server Common Web Administration (ESCWA) component used i
7.1HIGH
CVE-2023-23762
< 3.4.18
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an in
6.5MEDIUM
CVE-2023-23761
< 3.4.18
An improper authentication vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to modify o
7.7HIGH
CVE-2023-23760
< 3.4.17
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHu
4.9MEDIUM
CVE-2022-46257
>= 3.3.0 and < 3.3.17
An information disclosure vulnerability was identified in GitHub Enterprise Server that allowed private repositories to be added t
4.3MEDIUM
CVE-2023-22381
< 3.4.15
A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables fro
4.1MEDIUM
CVE-2023-22380
>= 3.7.0 and < 3.7.6
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed arbitrary file reading when building a GitH
6.5MEDIUM
CVE-2022-23739
< 3.3.16
An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for escalation of privileges in Grap
9.8CRITICAL
CVE-2022-46258
< 3.3.16
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with re
6.5MEDIUM
CVE-2022-23741
< 3.3.17
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a scoped user-to-server token to
7.2HIGH
CVE-2022-46256
< 3.3.17
A path traversal vulnerability was identified in GitHub Enterprise Server that allowed remote code execution when building a GitHu
8.8HIGH
CVE-2022-46255
all versions
An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabl
9.8CRITICAL
CVE-2022-23737
< 3.2.20
An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privile
6.5MEDIUM
CVE-2022-23740
all versions
CRITICAL: An improper neutralization of argument delimiters in a command vulnerability was identified in GitHub Enterprise Server
8.8HIGH
CVE-2022-23738
>= 3.2.0 and < 3.2.20
An improper cache key vulnerability was identified in GitHub Enterprise Server that allowed an unauthorized actor to access privat
5.7MEDIUM
CVE-2022-23734
< 3.2.16
A deserialization of untrusted data vulnerability was identified in GitHub Enterprise Server that could potentially lead to remote
8.8HIGH
CVE-2022-23733
>= 3.3.0 and < 3.3.11
A stored XSS vulnerability was identified in GitHub Enterprise Server that allowed the injection of arbitrary attributes. This inj
5.4MEDIUM
CVE-2022-23732
< 3.1.19
A path traversal vulnerability was identified in GitHub Enterprise Server management console that allowed the bypass of CSRF prote
8.8HIGH
CVE-2021-41599
>= 3.0.0 and < 3.0.21
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pa
8.8HIGH
CVE-2021-41598
< 3.0.21
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during
8.8HIGH
CVE-2021-22870
< 3.0.19
A path traversal vulnerability was identified in GitHub Pages builds on GitHub Enterprise Server that could allow an attacker to r
6.5MEDIUM
CVE-2021-22869
>= 3.0.0 and < 3.0.16
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to execute in a self-hosted runner gro
9.8CRITICAL
CVE-2021-22868
< 2.22.22
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages sit
4.3MEDIUM
CVE-2021-22867
< 2.22.17
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages sit
6.5MEDIUM
CVE-2021-22866
>= 2.20.0 and < 2.22.13
A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed more permissions to be granted during
8.8HIGH
CVE-2021-22865
< 2.21.18
An improper access control vulnerability was identified in GitHub Enterprise Server that allowed access tokens generated from a Gi
6.5MEDIUM
CVE-2021-22864
>= 2.21.0 and < 2.21.17
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pa
8.8HIGH
CVE-2020-9524
all versions
Cross Site scripting vulnerability on Micro Focus Enterprise Server and Enterprise developer, affecting all versions prior to vers
5.4MEDIUM
CVE-2020-9523
<= 3.0
Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all versio
8.8HIGH
CVE-2019-11651
all versions
Reflected XSS on Micro Focus Enterprise Developer and Enterprise Server, all versions prior to version 3.0 Patch Update 20, versio
6.1MEDIUM
CVE-2018-18940
all versions
servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary parameter=[XS
6.1MEDIUM
CVE-2018-12469
<= 2.3
Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web
7.5HIGH
CVE-2017-7424
all versions
A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1
6.5MEDIUM
CVE-2017-7423
all versions
A Cross-Site Request Forgery (CWE-352) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3,
8.8HIGH
CVE-2017-7422
all versions
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Ent
5.4MEDIUM
CVE-2017-7421
<= 2.3
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration
6.1MEDIUM
CVE-2017-7420
<= 2.3
An Authentication Bypass (CWE-287) vulnerability in ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise De
9.8CRITICAL
CVE-2017-5187
<= 2.3
A Cross-Site Request Forgery (CWE-352) vulnerability in Directory Server (aka Enterprise Server Administration web UI) in Micro Fo
8.8HIGH
CVE-2016-3126
<= 12.4
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows r
6.1MEDIUM
CVE-2016-1918
<= 12.4
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows r
6.1MEDIUM
CVE-2016-1917
<= 12.4
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows r
6.1MEDIUM
CVE-2016-1916
<= 12.4
Cross-site scripting (XSS) vulnerability in the Management Console in BlackBerry Enterprise Server (BES) 12 before 12.4.1 allows r
5.4MEDIUM
CVE-2015-4112
all versions
The Management Console in BlackBerry Enterprise Server (BES) 12 before 12.2 does not properly restrict use of FRAME elements, whic
CVE-2014-1469
<= 5.0.4
BlackBerry Enterprise Server 5.x before 5.0.4 MR7 and Enterprise Service 10.x before 10.2.2 log cleartext credentials during excep
CVE-2014-1467
<= 5.0.4
BlackBerry Enterprise Service 10 before 10.2.1, Universal Device Service 6, Enterprise Server Express for Domino through 5.0.4, En
CVE-2013-4854
all versions
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, a
CVE-2011-2162
all versions
Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2
CVE-2008-3246
all versions
Unspecified vulnerability in the PDF distiller component in the BlackBerry Attachment Service in BlackBerry Unite! 1.0 SP1 (1.0.1)
CVE-2004-0826
all versions
Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code v
CVE-2002-1655
all versions
The Web Publishing feature in Netscape Enterprise Server 3.x and iPlanet Web Server 4.x allows remote attackers to cause a denial
CVE-2002-1654
all versions
iPlanet Web Server Enterprise Edition and Netscape Enterprise Server 4.0 and 4.1 allows remote attackers to conduct HTTP Basic Aut
CVE-2002-1042
all versions
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6,
CVE-2001-0251
all versions
The Web Publishing feature in Netscape Enterprise Server 3.x allows remote attackers to cause a denial of service via the REVLOG c
CVE-2001-0250
all versions
The Web Publishing feature in Netscape Enterprise Server 4.x and earlier allows remote attackers to list arbitrary directories und
CVE-2000-0308
all versions
Insecure file permissions for Netscape FastTrack Server 2.x, Enterprise Server 2.0, and Proxy Server 2.5 in SCO UnixWare 7.0.x and
CVE-1999-0758
all versions
Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to
CVE-2000-0600
all versions
Netscape Enterprise Server in NetWare 5.1 allows remote attackers to cause a denial of service or execute arbitrary commands via a
CVE-2000-0236
all versions
Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web publishing t
CVE-2000-0237
all versions
Netscape Enterprise Server with Web Publishing enabled allows remote attackers to list arbitrary directories via a GET request for
CVE-1999-0744
all versions
Buffer overflow in Netscape Enterprise Server and FastTrask Server allows remote attackers to gain privileges via a long HTTP GET
CVE-1999-1005
all versions
Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) attack usin
CVE-1999-0853
all versions
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTT
CVE-1999-0751
all versions
Buffer overflow in Accept command in Netscape Enterprise Server 3.6 with the SSL Handshake Patch.
CVE-1999-1130
<= 3.5.1
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remote attacke
CVE-1999-0752
all versions
Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.
CVE-1999-0686
all versions
Denial of service in Netscape Enterprise Server (NES) in HP Virtual Vault (VVOS) via a long URL.
CVE-1999-0479
all versions
Denial of service Netscape Enterprise Server with VirtualVault on HP-UX VVOS systems.
CVE-1999-0269
all versions
Netscape Enterprise servers may list files through the PageServices query.
CVE-1999-0007
all versions
Information from SSL-encrypted sessions via PKCS #1.
CVE-1999-0012
all versions
Some web servers under Microsoft Windows allow remote attackers to bypass access restrictions for files with long file names.
7.0HIGH
CVE-1999-0045
all versions
List of arbitrary files on Web host via nph-test-cgi script.
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin