İçeriğe atla
Noroxi

yaws kayıtları

yaws üreticisine ait 11 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %9,1
Pre-auth RCE
2
Düzeltme kaydı olan
%81,8
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

11 kayıt
  • CVE-2017-10974
    54Planlayın

    Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.

    YüksekCVSS 7,5Kavram kanıtıEPSS %81

    yaws · yaws7 Tem 2017

  • CVE-2020-24916
    44Planlayın

    CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

    KritikCVSS 9,8İstismar yokEPSS %17

    yaws · yaws9 Eyl 2020

  • CVE-2020-24379
    40Planlayın

    WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.

    KritikCVSS 9,8İstismar yokEPSS %3

    yaws · yaws9 Eyl 2020

  • CVE-2011-4350
    31İzleyin

    Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed.

    OrtaCVSS 6,5SilahlaştırılmışEPSS %16

    yaws · yaws26 Kas 2019

  • yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications fr

    OrtaCVSS 6,1İstismar yokEPSS %1

    yaws · yaws10 Ara 2019

  • CVE-2009-0751
    23İzleyin

    Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of he

    OrtaCVSS 5,0Kavram kanıtıEPSS %10

    yaws · yaws2 Mar 2009

  • CVE-2009-4495
    23İzleyin

    Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's tit

    OrtaCVSS 5,0Kavram kanıtıEPSS %9

    yaws · yaws13 Oca 2010

  • CVE-2010-4181
    23İzleyin

    Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequenc

    OrtaCVSS 5,0Kavram kanıtıEPSS %8

    yaws · yaws4 Kas 2010

  • CVE-2020-12872
    22İzleyin

    yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if runnin

    OrtaCVSS 5,5İstismar yokEPSS %0

    yaws · yaws15 May 2020

  • CVE-2005-2008
    20İzleyin

    Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trai

    OrtaCVSS 5,0İstismar yokEPSS %1

    yaws · webserver17 Haz 2005

  • CVE-2011-5025
    18İzleyin

    Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web scri

    OrtaCVSS 4,3Kavram kanıtıEPSS %3

    yaws · yaws29 Ara 2011