Skip to content
Noroxi

boa records

12 published records for vendor boa.

All records

12 records
  • CVE-2007-4915
    60This week

    The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from ente

    CriticalCVSS 10.0WeaponizedEPSS 68%

    boa · boa webserverSep 17, 2007

  • /cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root priv

    HighCVSS 7.5Proof of conceptEPSS 68%

    boa · boaJun 23, 2017

  • Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.

    CriticalCVSS 9.8No exploitEPSS 2%

    boa · boaOct 11, 2019

  • Boa 0.94.14rc21 is vulnerable to SQL Injection via username.

    CriticalCVSS 9.8No exploitEPSS 1%

    boa · boaNov 23, 2022

  • Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, l

    HighCVSS 7.5Proof of conceptEPSS 12%

    boa · boaMay 27, 2021

  • Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.

    HighCVSS 7.5No exploitEPSS 2%

    boa · boaOct 11, 2019

  • CVE-2016-9564
    30Monitor

    Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with

    HighCVSS 7.5No exploitEPSS 1%

    boa · boaNov 30, 2016

  • Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects

    HighCVSS 7.5No exploitEPSS 1%

    boa-dev · boaAug 15, 2024

  • Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    HighCVSS 7.5No exploitEPSS 1%

    boa web server · boa web server 0.94.14rc21Nov 14, 2024

  • CVE-2009-4496
    24Monitor

    Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window

    MediumCVSS 5.0Proof of conceptEPSS 12%

    boa · boaJan 13, 2010

  • CVE-2000-0920
    23Monitor

    Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified ..

    MediumCVSS 5.0Proof of conceptEPSS 8%

    boa · boa webserverDec 19, 2000

  • Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone t

    MediumCVSS 5.3No exploitEPSS 1%

    boa · boaDec 12, 2022