Jasper records
5 published records for vendor jasper.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 40%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-134 Use of Externally-Controlled Format String2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-255 Credentials Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2009-3711Weaponized | Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a djasper · httpdx · CWE-119 | Critical10.0 | — | 63.9% | Oct 16, 2009 |
48Plan | CVE-2009-4769Weaponized | Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execjasper · httpdx · CWE-134 | Critical9.3 | — | 37.9% | Apr 20, 2010 |
44Plan | CVE-2009-3663Proof of concept | Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of sejasper · httpdx · CWE-134 | Critical10.0 | — | 14.6% | Oct 11, 2009 |
30Monitor | CVE-2009-4770No exploit | The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makjasper · httpdx · CWE-255 | High7.5 | — | 1.3% | Apr 20, 2010 |
22Monitor | CVE-2009-4531Proof of concept | httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a .jasper · httpdx · CWE-200 | Medium5.0 | — | 7.1% | Dec 31, 2009 |
- CVE-2009-371159Plan
Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a d
CriticalCVSS 10.0WeaponizedEPSS 64%jasper · httpdxOct 16, 2009
- CVE-2009-476948Plan
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to exec
CriticalCVSS 9.3WeaponizedEPSS 38%jasper · httpdxApr 20, 2010
- CVE-2009-366344Plan
Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of se
CriticalCVSS 10.0Proof of conceptEPSS 15%jasper · httpdxOct 11, 2009
- CVE-2009-477030Monitor
The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which mak
HighCVSS 7.5No exploitEPSS 1%jasper · httpdxApr 20, 2010
- CVE-2009-453122Monitor
httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a .
MediumCVSS 5.0Proof of conceptEPSS 7%jasper · httpdxDec 31, 2009