apsis records
5 published records for vendor apsis.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-10711No exploit | Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.apsis · pound · CWE-444 | Critical9.8 | — | 2.8% | Jan 29, 2018 |
36Monitor | CVE-2018-21245No exploit | Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.apsis · pound · CWE-444 | Critical9.1 | — | 1.1% | Jun 15, 2020 |
32Monitor | CVE-2004-2026Proof of concept | Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via apsis · pound | High7.5 | — | 6.6% | Dec 31, 2004 |
32Monitor | CVE-2005-1391No exploit | Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host apsis · pound | High7.5 | — | 6.1% | May 3, 2005 |
17Monitor | CVE-2005-3751No exploit | HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall proapsis · pound | Medium4.3 | — | 1.5% | Nov 22, 2005 |
- CVE-2016-1071140Plan
Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
CriticalCVSS 9.8No exploitEPSS 3%apsis · poundJan 29, 2018
- CVE-2018-2124536Monitor
Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.
CriticalCVSS 9.1No exploitEPSS 1%apsis · poundJun 15, 2020
- CVE-2004-202632Monitor
Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via
HighCVSS 7.5Proof of conceptEPSS 7%apsis · poundDec 31, 2004
- CVE-2005-139132Monitor
Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host
HighCVSS 7.5No exploitEPSS 6%apsis · poundMay 3, 2005
- CVE-2005-375117Monitor
HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall pro
MediumCVSS 4.3No exploitEPSS 1%apsis · poundNov 22, 2005