ncsa records
8 published records for vendor ncsa.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 25%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
66This week | CVE-1999-0067No exploit | phf CGI program allows remote command execution through shell metacharacters.apache · http server · CWE-78 | Critical10.0 | — | 86.9% | Mar 20, 1996 |
42Plan | CVE-1999-0235Proof of concept | Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.ncsa · ncsa web server | Critical10.0 | — | 6.6% | Feb 17, 1995 |
38Monitor | CVE-2005-0468Proof of concept | Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute ancsa · telnet | High7.5 | — | 27.1% | May 2, 2005 |
34Monitor | CVE-1999-0146Proof of concept | The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return charncsa · campas | High7.5 | — | 14.9% | Jul 15, 1997 |
33Monitor | CVE-1999-0267Proof of concept | Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.ncsa · ncsa httpd | High7.5 | — | 10.2% | Sep 23, 1997 |
33Monitor | CVE-2005-0469No exploit | Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackerncsa · telnet | High7.5 | — | 8.9% | May 2, 2005 |
30Monitor | CVE-1999-1090No exploit | The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which ncsa · telnet | High7.5 | — | 1.7% | Sep 10, 1991 |
17Monitor | CVE-2011-0738No exploit | MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.5globus · globus toolkit · CWE-20 | Medium4.3 | — | 1.6% | Feb 1, 2011 |
- CVE-1999-006766This week
phf CGI program allows remote command execution through shell metacharacters.
CriticalCVSS 10.0No exploitEPSS 87%apache · http serverMar 20, 1996
- CVE-1999-023542Plan
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
CriticalCVSS 10.0Proof of conceptEPSS 7%ncsa · ncsa web serverFeb 17, 1995
- CVE-2005-046838Monitor
Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute a
HighCVSS 7.5Proof of conceptEPSS 27%ncsa · telnetMay 2, 2005
- CVE-1999-014634Monitor
The campas CGI program provided with some NCSA web servers allows an attacker to execute arbitrary commands via encoded carriage return char
HighCVSS 7.5Proof of conceptEPSS 15%ncsa · campasJul 15, 1997
- CVE-1999-026733Monitor
Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.
HighCVSS 7.5Proof of conceptEPSS 10%ncsa · ncsa httpdSep 23, 1997
- CVE-2005-046933Monitor
Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attacker
HighCVSS 7.5No exploitEPSS 9%ncsa · telnetMay 2, 2005
- CVE-1999-109030Monitor
The default configuration of NCSA Telnet package for Macintosh and PC enables FTP, even though it does not include an "ftp=yes" line, which
HighCVSS 7.5No exploitEPSS 2%ncsa · telnetSep 10, 1991
- CVE-2011-073817Monitor
MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.5
MediumCVSS 4.3No exploitEPSS 2%globus · globus toolkitFeb 1, 2011