Skip to content
Noroxi

Apachefriends records

14 published records for vendor apachefriends.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

14 records
  • An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows.

    HighCVSS 8.8Proof of conceptEPSS 22%

    apachefriends · xamppApr 2, 2020

  • XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    apachefriends · xamppMay 14, 2019

  • CVE-2024-0338
    39Monitor

    Buffer Overflow Vulnerability in XAMPP

    CriticalCVSS 9.8No exploitEPSS 0%

    apachefriends · xamppFeb 2, 2024

  • Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute a

    HighCVSS 8.8No exploitEPSS 1%

    apachefriends · xamppMay 23, 2022

  • CVE-2009-0919
    33Monitor

    XAMPP installs multiple packages with insecure default passwords, which makes it easier for remote attackers to obtain access via (1) the "l

    HighCVSS 7.5No exploitEPSS 9%

    apachefriends · xamppMar 16, 2009

  • XAMPP Installer uncontrolled search path

    HighCVSS 7.8No exploitEPSS 1%

    apachefriends · xamppJun 9, 2022

  • CVE-2024-5055
    30Monitor

    Vulnerability of uncontrolled resource consumption in XAMPP

    HighCVSS 7.5No exploitEPSS 0%

    apache friends · xamppMay 17, 2024

  • CVE-2008-6498
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in security/xamppsecurity.php in XAMPP 1.6.8 allows remote attackers to hijack the authentic

    MediumCVSS 6.8Proof of conceptEPSS 1%

    apachefriends · xamppMar 19, 2009

  • CVE-2019-8924
    26Monitor

    XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter.

    MediumCVSS 6.1Proof of conceptEPSS 6%

    apachefriends · xamppMay 16, 2019

  • The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory.

    MediumCVSS 6.7No exploitEPSS 0%

    apachefriends · xamppSep 12, 2023

  • CVE-2019-8920
    24Monitor

    iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.

    MediumCVSS 6.1No exploitEPSS 1%

    apachefriends · xamppJul 9, 2019

  • CVE-2008-6499
    22Monitor

    security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows remote attackers to sp

    MediumCVSS 5.5Proof of conceptEPSS 2%

    apachefriends · xamppMar 19, 2009

  • CVE-2013-2586
    19Monitor

    XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-si

    MediumCVSS 4.3Proof of conceptEPSS 5%

    apachefriends · xamppSep 29, 2014

  • CVE-2006-4994
    18Monitor

    Multiple unquoted Windows search path vulnerabilities in Apache Friends XAMPP 1.5.2 might allow local users to gain privileges via a malicio

    MediumCVSS 4.6No exploitEPSS 0%

    apachefriends · xamppSep 25, 2006