Skip to content
Noroxi

an records

8 published records for vendor an.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

      The weakness classes this vendor ships most often: where to look.

      CWE

      All records

      8 records
      • CVE-2002-1930
        32Monitor

        Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username.

        HighCVSS 7.5Proof of conceptEPSS 5%

        an · an-httpdDec 31, 2002

      • CVE-2006-1598
        32Monitor

        AN HTTPD 1.42n, and possibly other versions before 1.42p, allows remote attackers to obtain source code of scripts via crafted requests with

        HighCVSS 7.8No exploitEPSS 2%

        an · an-httpdApr 3, 2006

      • CVE-1999-0947
        31Monitor

        AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via

        HighCVSS 7.5Proof of conceptEPSS 3%

        an · an-httpdNov 2, 1999

      • CVE-2005-1086
        27Monitor

        Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with

        MediumCVSS 6.4Proof of conceptEPSS 6%

        an · an-httpdMay 2, 2005

      • CVE-2005-1087
        26Monitor

        CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfi

        MediumCVSS 6.4Proof of conceptEPSS 2%

        an · an-httpdApr 7, 2005

      • CVE-2003-1269
        21Monitor

        AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks t

        MediumCVSS 5.0No exploitEPSS 2%

        an · an-httpDec 31, 2003

      • CVE-2003-1270
        20Monitor

        AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possib

        MediumCVSS 5.0No exploitEPSS 1%

        an · an-httpDec 31, 2003

      • CVE-2003-1271
        18Monitor

        Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via

        MediumCVSS 4.3Proof of conceptEPSS 2%

        an · an-httpDec 31, 2003