mbedthis software records
6 published records for vendor mbedthis software.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
21Monitor | CVE-2004-2315No exploit | Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via an empty OPTIONS request.mbedthis software · mbedthis appweb http server | Medium5.0 | — | 1.7% | Dec 31, 2004 |
21Monitor | CVE-2004-2316No exploit | Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via a GET request containing an MS-DOSmbedthis software · mbedthis appweb http server | Medium5.0 | — | 1.7% | Dec 31, 2004 |
20Monitor | CVE-2004-2213No exploit | Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) tmbedthis software · mbedthis appweb http server | Medium5.0 | — | 1.4% | Dec 31, 2004 |
20Monitor | CVE-2004-2317No exploit | Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user messagembedthis software · mbedthis appweb http server | Medium5.0 | — | 1.2% | Dec 31, 2004 |
18Monitor | CVE-2007-3009Proof of concept | Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the confimbedthis software · mbedthis appweb http server | Medium4.3 | — | 2.2% | Jun 4, 2007 |
17Monitor | CVE-2007-3008No exploit | Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and crmbedthis software · mbedthis appweb http server · CWE-79 | Medium4.3 | — | 1.5% | Jun 4, 2007 |
- CVE-2004-231521Monitor
Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via an empty OPTIONS request.
MediumCVSS 5.0No exploitEPSS 2%mbedthis software · mbedthis appweb http serverDec 31, 2004
- CVE-2004-231621Monitor
Mbedthis AppWeb HTTP server before 1.0.2 allows remote attackers to cause a denial of service (crash) via a GET request containing an MS-DOS
MediumCVSS 5.0No exploitEPSS 2%mbedthis software · mbedthis appweb http serverDec 31, 2004
- CVE-2004-221320Monitor
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to obtain the source code for scripts via a (1) trailing dot (".") or (2) t
MediumCVSS 5.0No exploitEPSS 1%mbedthis software · mbedthis appweb http serverDec 31, 2004
- CVE-2004-231720Monitor
Information leak in Mbedthis AppWeb HTTP server 1.0 through 1.1.2 allows remote attackers to obtain sensitive information via a user message
MediumCVSS 5.0No exploitEPSS 1%mbedthis software · mbedthis appweb http serverDec 31, 2004
- CVE-2007-300918Monitor
Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the confi
MediumCVSS 4.3Proof of conceptEPSS 2%mbedthis software · mbedthis appweb http serverJun 4, 2007
- CVE-2007-300817Monitor
Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cr
MediumCVSS 4.3No exploitEPSS 1%mbedthis software · mbedthis appweb http serverJun 4, 2007