yaws kayıtları
yaws üreticisine ait 11 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %9,1
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %81,8
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-326 Inadequate Encryption Strength1
- CWE-399 Resource Management Errors1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
11 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
54Planlayın | CVE-2017-10974Kavram kanıtı | Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.yaws · yaws · CWE-22 | Yüksek7,5 | — | %81,2 | 7 Tem 2017 |
44Planlayın | CVE-2020-24916İstismar yok | CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.yaws · yaws · CWE-78 | Kritik9,8 | — | %17,4 | 9 Eyl 2020 |
40Planlayın | CVE-2020-24379İstismar yok | WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.yaws · yaws · CWE-611 | Kritik9,8 | — | %3,4 | 9 Eyl 2020 |
31İzleyin | CVE-2011-4350Silahlaştırılmış | Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed.yaws · yaws · CWE-22 | Orta6,5 | — | %16,1 | 26 Kas 2019 |
24İzleyin | CVE-2016-1000108İstismar yok | yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications fryaws · yaws · CWE-601 | Orta6,1 | — | %1,1 | 10 Ara 2019 |
23İzleyin | CVE-2009-0751Kavram kanıtı | Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of heyaws · yaws · CWE-399 | Orta5,0 | — | %10,4 | 2 Mar 2009 |
23İzleyin | CVE-2009-4495Kavram kanıtı | Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's tityaws · yaws · CWE-20 | Orta5,0 | — | %9,0 | 13 Oca 2010 |
23İzleyin | CVE-2010-4181Kavram kanıtı | Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequencyaws · yaws · CWE-22 | Orta5,0 | — | %8,5 | 4 Kas 2010 |
22İzleyin | CVE-2020-12872İstismar yok | yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if runninyaws · yaws · CWE-326 | Orta5,5 | — | %0,4 | 15 May 2020 |
20İzleyin | CVE-2005-2008İstismar yok | Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a traiyaws · webserver | Orta5,0 | — | %1,5 | 17 Haz 2005 |
18İzleyin | CVE-2011-5025Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web scriyaws · yaws · CWE-79 | Orta4,3 | — | %2,7 | 29 Ara 2011 |
- CVE-2017-1097454Planlayın
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.
YüksekCVSS 7,5Kavram kanıtıEPSS %81yaws · yaws7 Tem 2017
- CVE-2020-2491644Planlayın
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
KritikCVSS 9,8İstismar yokEPSS %17yaws · yaws9 Eyl 2020
- CVE-2020-2437940Planlayın
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
KritikCVSS 9,8İstismar yokEPSS %3yaws · yaws9 Eyl 2020
- CVE-2011-435031İzleyin
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed.
OrtaCVSS 6,5SilahlaştırılmışEPSS %16yaws · yaws26 Kas 2019
- CVE-2016-100010824İzleyin
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications fr
OrtaCVSS 6,1İstismar yokEPSS %1yaws · yaws10 Ara 2019
- CVE-2009-075123İzleyin
Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of he
OrtaCVSS 5,0Kavram kanıtıEPSS %10yaws · yaws2 Mar 2009
- CVE-2009-449523İzleyin
Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's tit
OrtaCVSS 5,0Kavram kanıtıEPSS %9yaws · yaws13 Oca 2010
- CVE-2010-418123İzleyin
Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequenc
OrtaCVSS 5,0Kavram kanıtıEPSS %8yaws · yaws4 Kas 2010
- CVE-2020-1287222İzleyin
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if runnin
OrtaCVSS 5,5İstismar yokEPSS %0yaws · yaws15 May 2020
- CVE-2005-200820İzleyin
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trai
OrtaCVSS 5,0İstismar yokEPSS %1yaws · webserver17 Haz 2005
- CVE-2011-502518İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web scri
OrtaCVSS 4,3Kavram kanıtıEPSS %3yaws · yaws29 Ara 2011