Skip to content
Noroxi

crowcpp records

6 published records for vendor crowcpp.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

6 records
  • Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    crowcpp · crowAug 4, 2022

  • HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used.

    CriticalCVSS 9.8No exploitEPSS 3%

    crowcpp · crowAug 22, 2022

  • This affects the package Crow before 0.3+4.

    HighCVSS 7.5No exploitEPSS 2%

    crowcpp · crowJan 13, 2022

  • HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfillin

    HighCVSS 7.5No exploitEPSS 1%

    crowcpp · crowAug 22, 2022

  • This affects the package Crow before 0.3+4.

    MediumCVSS 6.1No exploitEPSS 1%

    crowcpp · crowJan 13, 2022

  • All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values.

    MediumCVSS 6.1No exploitEPSS 1%

    crowcpp · crowSep 12, 2023