← Vulnerability feed

Vulnerability record · CVE-2007-2680 · published 15 May 2007

CVE-2007-2680: Canon network camera server vb100 vulnerability

Canon · Network Camera Server Vb100

Cross-site scripting (XSS) vulnerability in the management interface in Canon Network Camera Server VB100 and VB101 with firmware 3.0 R69 and earlier, and VB150 with firmware 1.1 R39 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

4.3 CVSS 2.0 Medium EPSS 1.2% · top 32.4%
4.3CVSS 2.0 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the management interface in Canon Network Camera Server VB100 and VB101 with firmware 3.0 R69 and earlier, and VB150 with firmware 1.1 R39 and earlier, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2680 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2006-1185Microsoft Internet Explorer memory corruption via invalid HTMLCVE-2006-1185 is an unspecified memory corruption flaw in Microsoft Internet Explorer 5.01 through 6 that is triggered by certain invalid HTML. Succe…EPSS 70%analysed7.5CVE-2006-1188Internet Explorer memory corruption via crafted HTML tagMicrosoft Internet Explorer 5.01 through 6 contains a memory corruption flaw triggered by HTML elements with a certain crafted tag. A remote attacker…EPSS 58%analysed7.5CVE-2005-4827Microsoft ie vulnerabilityInternet Explorer 6.0, and possibly other versions, allows remote attackers to bypass the same origin security policy and make requests outside of th…EPSS 11%5.0CVE-2006-7065Microsoft ie vulnerabilityMicrosoft Internet Explorer allows remote attackers to cause a denial of service (crash) via an IFRAME with a certain XML file and XSL stylesheet tha…EPSS 21%5.0CVE-2006-3354Microsoft ie vulnerabilityMicrosoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Filter property of an ADODB.Recordset Activ…EPSS 17%4.0CVE-2006-2900Microsoft ie information exposure vulnerabilityInternet Explorer 6 allows user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filenam…EPSS 13%2.6CVE-2006-1192Microsoft ie improper input validation vulnerabilityMicrosoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the tru…EPSS 32%

Source: NIST National Vulnerability Database (record CVE-2007-2680), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.