Time from Exploit Publish Date to Vendor Solution Date

This page presents a list of vulnerabilities with the longest "time of exposure". This is calculated by looking at the exploit publication date and the vendor solution date. During this period, consumers may be vulnerable to the issue while public exploit code exists, allowing for easier and more widespread attacks.

Key 270+ Days 180-269 Days 0-179 Days

<< Back to Browse

ID Disc Date Days of Exposure Title
73824 2011-07-13 657437 days TCExam /admin/code/tce_edit_backup.php backup_file Parameter XSS
15631 2005-03-31 12873 days PHP Multiple Unspecified Issues
93240 2001-03-25 4422 days MIT Kerberos 5 kpasswd Service Spoofed Packet Remote DoS
90171 2003-09-02 3367 days GNU C Library (glibc) printf() Incomplete Multibyte Sequence Handling Infinite Loop DoS
49736 2000-08-15 3011 days Microsoft Windows SMB NTLM Authentication Credential Replay Remote Code Execution
88592 2005-01-16 2872 days phpGiftReq index.php Multiple Parameter SQL Injection
88591 2005-01-16 2872 days phpGiftReq item.php itemid Parameter SQL Injection
54837 2001-02-02 2593 days IBM WebSphere Application Server (WAS) Traversal Error Page XSS
88569 1995-07-12 2424 days HP-UX FTP Server (ftpd) Privileged Port Scan Bounce Weakness
59037 2002-12-01 2016 days Thatware auth.inc.php user Parameter SQL Injection
829 2001-07-02 1628 days IBM WebSphere Application Server (WAS) Java Servlet Error Page XSS
15123 2005-03-30 1549 days Kerio Personal Firewall Network Rules Process Masquerade Local Bypass
14987 2004-03-26 1537 days XMB Forum post.php Multiple Parameter XSS
33567 2004-06-17 1423 days XMB U2U Instant Messenger memcp.php recipient Field XSS
91766 2003-08-26 1407 days dpkg Tar Archive Extraction Incorrect File Permissions Setting Weakness
5854 1996-05-21 1302 days NetKit inetd SYN/RST Half-open Packet Scan Remote DoS
88201 2007-08-10 1222 days SpringSource Hyperic HQ Sybase Database Plugin Monitor Perl Script Local Password Disclosure
86509 2009-04-22 1140 days Mozilla Firefox Malformed Quoted src XSS Weakness
73563 2008-02-01 1117 days Universal Feed Parser (feedparser) feedparser.py DOCTYPE Declaration DoS
36802 2007-06-04 1057 days Madirish Webmail lib/addressbook.php GLOBALS[basedir] Parameter Remote File Inclusion
88572 1995-07-13 1023 days Digital Unix FTP Server (ftpd) Privileged Port Scan Bounce Weakness
90797 2008-05-27 963 days Cerberus Helpdesk Arbitrary Group Custom Fields Disclosure
66441 2008-04-12 950 days Siemens SIMATIC WinCC SQL Database Default Password
12368 2004-12-09 942 days UseModWiki wiki.pl XSS
33130 2007-02-08 922 days HP Network Node Manager (NNM) Remote Console Directory Permission Weakness Privilege Escalation
86511 2010-04-21 776 days Mozilla Firefox HTML5 Parser Malformed script Tag Parsing XSS Weakness
24631 2006-04-09 762 days XMB Forum .swf Actionscript Execution
14238 2005-02-25 758 days BadBlue ext.dll mfcisapicommand Parameter Remote Overflow
9030 1997-09-03 741 days NetKit (biff+comsat) in.comsat Message Flood Remote DoS
47358 2008-08-03 733 days XEROX Phaser 8400 UDP Packet Handling Remote DoS
15537 2005-04-18 727 days PayProCart usrauthstamp.php IP Disclosure
90276 2010-05-24 712 days Apache Axis2 axis2.xml Plaintext Password Local Disclosure
24166 2006-03-27 622 days phpmyfamily track.php name Parameter XSS
24167 2006-03-27 622 days phpmyfamily index.php PHPSESSID CRLF Injection Path Disclosure
42186 2008-02-14 582 days PHP Live! admin/traffic/knowledge_searchm.php questid Parameter SQL Injection
42559 2008-02-28 473 days Podcast Generator loadparser.php absoluteurl Parameter Remote File Inclusion
42560 2008-02-28 473 days Podcast Generator admin.php absoluteurl Parameter Remote File Inclusion
42562 2008-02-28 473 days Podcast Generator categories_add.php absoluteurl Parameter Remote File Inclusion
42563 2008-02-28 473 days Podcast Generator categories_remove.php absoluteurl Parameter Remote File Inclusion
42564 2008-02-28 473 days Podcast Generator edit.php absoluteurl Parameter Remote File Inclusion
42565 2008-02-28 473 days Podcast Generator editdel.php absoluteurl Parameter Remote File Inclusion
42566 2008-02-28 473 days Podcast Generator ftpfeature.php absoluteurl Parameter Remote File Inclusion
42567 2008-02-28 473 days Podcast Generator login.php absoluteurl Parameter Remote File Inclusion
42568 2008-02-28 473 days Podcast Generator pgRSSnews.php absoluteurl Parameter Remote File Inclusion
42569 2008-02-28 473 days Podcast Generator showcat.php absoluteurl Parameter Remote File Inclusion
42570 2008-02-28 473 days Podcast Generator upload.php absoluteurl Parameter Remote File Inclusion
42571 2008-02-28 473 days Podcast Generator archive_cat.php absoluteurl Parameter Remote File Inclusion
42572 2008-02-28 473 days Podcast Generator archive_nocat.php absoluteurl Parameter Remote File Inclusion
42573 2008-02-28 473 days Podcast Generator recent_list.php absoluteurl Parameter Remote File Inclusion
25073 2006-04-28 434 days Microsoft IE mhtml: Redirection Domain Restriction Bypass
73566 2009-11-18 433 days Universal Feed Parser (feedparser) feedparser.py Nested CDATA Stanza XSS
91405 2012-01-03 409 days Inkscape /tmp Directory EPS File Loading Weakness
87943 2011-04-04 407 days Facter Search Path Subversion Local Privilege Escalation
75902 2011-01-20 405 days WebCalendar Multiple Script Direct Request Path Disclosure
32693 2007-01-17 390 days Apple Mac OS X Minimal SLP v2 Service Agent (slpd) Registration Request Overflow
57735 1990-04-11 371 days expreserve /tmp/Ex$PID Race Condition Arbitrary File Ownership Modification
41199 2007-12-14 368 days Drake CMS index.php option Parameter XSS
41494 2008-02-07 365 days Adobe Reader / Acrobat EScript.api Plug-in Crafted PDF Arbitrary Code Execution
64540 2010-03-23 359 days SAP GUI SAPBExCommonResources.BExGlobal ActiveX Arbitrary Command Execution
49325 2008-10-13 357 days Oracle Database Workspace Manager SYS.LT.MERGEWORKSPACE SQL Injection
81872 2012-05-04 357 days GetSimple CMS admin/upload.php path Parameter XSS
14993 2005-03-21 345 days XMB Profile Mood Variables XSS
76456 2011-06-29 342 days IBM DB2 Tivoli Monitoring Agent (ITMA) db2rspgn libkbb.so Path Subversion Arbitrary DLL Injection Code Execution
76457 2011-06-29 342 days IBM DB2 Tivoli Monitoring Agent (ITMA) kbbacf1 libkbb.so Path Subversion Arbitrary DLL Injection Code Execution
72411 2011-05-18 321 days Room Juice display.php filename Parameter XSS
21488 2005-12-01 320 days Interspire FastFind index.php query Parameter XSS
30214 2006-11-06 296 days Microsoft Windows GDI Kernel Structure Modification Code Execution
53333 2009-03-23 295 days Apple Mac OS X XNU User Space Interaction Restriction Weakness Local Privilege Escalation
60586 2009-12-01 292 days phpMyFAQ index.php Multiple Parameter XSS
59001 2009-03-20 290 days Apache Axis2 xsd Parameter Traversal Arbitrary File Disclosure
23899 2006-03-14 289 days Microsoft Office Excel BIFF File Processing Malformed BOOLERR Record Arbitrary Code Execution
35128 2007-03-11 270 days AssetMan download_pdf.php pdf_file Parameter Traversal Arbitrary File Access
78341 2012-01-15 264 days ATutor Multiple Script PATH_INFO Parameter XSS
92241 2010-10-07 259 days Apple Mac OS X tnftpd Server Process GLOB_LIMIT Crafted Command Pattern Remote DoS
15465 2005-04-12 236 days Microsoft IE DHTML Object Memory Corruption Code Execution
8101 2001-07-02 233 days UnZip Double Dot Arbitrary File Overwrite
8102 2001-07-02 233 days UnZip Single Slash Arbitrary File Overwrite
82664 2012-05-26 228 days Store Locator Plus Plugin for WordPress /wp-content/plugins/store-locator-le/downloadcsv.php query Parameter SQL Injection
88795 1991-04-01 224 days SunOS rpc.mountd /etc/exports -access Truncation Remote File System World Mounting Weakness
72406 2011-05-18 224 days Opera Frameset Construct Handling Memory Corruption
64918 2009-09-25 224 days html2ps SSI include Directive Traversal Arbitrary File Access
71190 2011-02-23 222 days Local Market Explorer Plugin for WordPress wp-content/plugins/local-market-explorer/modules/walk-score-iframe.php api-key Parameter XSS
72108 2011-05-01 214 days Tine library/vcardphp/vbook.php file Parameter XSS
91097 2007-09-19 212 days IBM WebSphere Application Server (WAS) Cached Credential Authentication Policy Bypass
56531 2009-01-13 211 days Premier Election Solutions (Diebold) Global Election Management System (GEMS) Clear Button Audit Log Deletion
66388 2010-07-15 206 days XMB Admin Password Manipulation CSRF
78132 2012-01-03 205 days OpenEMR validateUser.php u Parameter SQL Injection
92730 2009-07-19 205 days SLiM on Debian Linux /tmp/slim.png Symlink Arbitrary File Overwrite
75218 2011-09-06 196 days Blue Coat Reporter Encoded Traversal Arbitary File Access
899 1997-05-07 195 days IRIX syserr /usr/tmp/.syserr.data Symlink Arbitrary File Corruption
83568 2001-09-17 194 days BookMark4U IP-based Access Authentication Bypass
78548 2012-01-26 193 days phpList admin/index.php Multiple Parameter XSS
84588 2012-08-06 192 days HP ArcSight Connector / Logger Appliances File Host Data Handling XSS
58941 2008-12-17 183 days BIRT birt-viewer/run __report Parameter XSS
32769 2007-03-01 182 days PHP Zend Engine Variable Destruction Deep Recursion Overflow
73474 2011-05-12 181 days GEAR CD DVD Filter Driver GEARAspiWDM.sys Pointers Table Invalid Memory Access Local DoS
73475 2011-05-12 181 days GEAR CD DVD Filter Driver GEARAspiWDM.sys Pointers Table Array Indexing Error Invalid Memory Access Local DoS
78486 2012-01-19 181 days Rockwell Automation Multiple Product Multiple Parameter Manipulation CIP Message Parsing Remote DoS
78487 2012-01-20 181 days Rockwell Automation Multiple Product CIP Packet Parsing Remote Overflow CPU DoS
78488 2012-01-20 181 days Rockwell Automation Multiple Product CIP Packet Parsing Remote Overflow NIC DoS

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use