webdav records
5 published records for vendor webdav.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-134 Use of Externally-Controlled Format String1
- CWE-326 Inadequate Encryption Strength1
- CWE-399 Resource Management Errors1
- CWE-787 Out-of-bounds Write1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2004-0398No exploit | Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadavwebdav · cadaver · CWE-787 | High7.5 | — | 5.0% | Jul 7, 2004 |
30Monitor | CVE-2004-0179Proof of concept | Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversiowebdav · neon · CWE-134 | Medium6.8 | — | 11.1% | Jun 1, 2004 |
23Monitor | CVE-2009-2474No exploit | neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name webdav · neon · CWE-326 | Medium5.8 | — | 1.5% | Aug 21, 2009 |
20Monitor | CVE-2009-2473Proof of concept | neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackerswebdav · neon · CWE-399 | Medium4.3 | — | 8.4% | Aug 21, 2009 |
18Monitor | CVE-2008-3746No exploit | neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Diwebdav · neon | Medium4.3 | — | 2.3% | Aug 27, 2008 |
- CVE-2004-039832Monitor
Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadav
HighCVSS 7.5No exploitEPSS 5%webdav · cadaverJul 7, 2004
- CVE-2004-017930Monitor
Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversio
MediumCVSS 6.8Proof of conceptEPSS 11%webdav · neonJun 1, 2004
- CVE-2009-247423Monitor
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name
MediumCVSS 5.8No exploitEPSS 1%webdav · neonAug 21, 2009
- CVE-2009-247320Monitor
neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers
MediumCVSS 4.3Proof of conceptEPSS 8%webdav · neonAug 21, 2009
- CVE-2008-374618Monitor
neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Di
MediumCVSS 4.3No exploitEPSS 2%webdav · neonAug 27, 2008