an records
8 published records for vendor an.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2002-1930Proof of concept | Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username.an · an-httpd | High7.5 | — | 5.5% | Dec 31, 2002 |
32Monitor | CVE-2006-1598No exploit | AN HTTPD 1.42n, and possibly other versions before 1.42p, allows remote attackers to obtain source code of scripts via crafted requests withan · an-httpd | High7.8 | — | 1.9% | Apr 3, 2006 |
31Monitor | CVE-1999-0947Proof of concept | AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via an · an-httpd | High7.5 | — | 3.2% | Nov 2, 1999 |
27Monitor | CVE-2005-1086Proof of concept | Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request withan · an-httpd | Medium6.4 | — | 5.6% | May 2, 2005 |
26Monitor | CVE-2005-1087Proof of concept | CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfian · an-httpd | Medium6.4 | — | 2.3% | Apr 7, 2005 |
21Monitor | CVE-2003-1269No exploit | AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks tan · an-http | Medium5.0 | — | 2.1% | Dec 31, 2003 |
20Monitor | CVE-2003-1270No exploit | AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possiban · an-http | Medium5.0 | — | 1.4% | Dec 31, 2003 |
18Monitor | CVE-2003-1271Proof of concept | Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users viaan · an-http | Medium4.3 | — | 1.8% | Dec 31, 2003 |
- CVE-2002-193032Monitor
Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username.
HighCVSS 7.5Proof of conceptEPSS 5%an · an-httpdDec 31, 2002
- CVE-2006-159832Monitor
AN HTTPD 1.42n, and possibly other versions before 1.42p, allows remote attackers to obtain source code of scripts via crafted requests with
HighCVSS 7.8No exploitEPSS 2%an · an-httpdApr 3, 2006
- CVE-1999-094731Monitor
AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via
HighCVSS 7.5Proof of conceptEPSS 3%an · an-httpdNov 2, 1999
- CVE-2005-108627Monitor
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with
MediumCVSS 6.4Proof of conceptEPSS 6%an · an-httpdMay 2, 2005
- CVE-2005-108726Monitor
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfi
MediumCVSS 6.4Proof of conceptEPSS 2%an · an-httpdApr 7, 2005
- CVE-2003-126921Monitor
AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks t
MediumCVSS 5.0No exploitEPSS 2%an · an-httpDec 31, 2003
- CVE-2003-127020Monitor
AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possib
MediumCVSS 5.0No exploitEPSS 1%an · an-httpDec 31, 2003
- CVE-2003-127118Monitor
Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via
MediumCVSS 4.3Proof of conceptEPSS 2%an · an-httpDec 31, 2003