Skip to content
Noroxi

apsis records

5 published records for vendor apsis.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
100%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 20

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

5 records
  • Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.

    CriticalCVSS 9.8No exploitEPSS 3%

    apsis · poundJan 29, 2018

  • Pound before 2.8 allows HTTP request smuggling, a related issue to CVE-2016-10711.

    CriticalCVSS 9.1No exploitEPSS 1%

    apsis · poundJun 15, 2020

  • CVE-2004-2026
    32Monitor

    Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via

    HighCVSS 7.5Proof of conceptEPSS 7%

    apsis · poundDec 31, 2004

  • CVE-2005-1391
    32Monitor

    Buffer overflow in the add_port function in APSIS Pound 1.8.2 and earlier allows remote attackers to execute arbitrary code via a long Host

    HighCVSS 7.5No exploitEPSS 6%

    apsis · poundMay 3, 2005

  • CVE-2005-3751
    17Monitor

    HTTP request smuggling vulnerability in Pound before 1.9.4 allows remote attackers to poison web caches, bypass web application firewall pro

    MediumCVSS 4.3No exploitEPSS 1%

    apsis · poundNov 22, 2005