Записи an
8 опубликованных записей вендора an.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2002-1930Proof of concept | Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username.an · an-httpd | Высокая7,5 | — | 5,5 % | 31 дек. 2002 г. |
32Наблюдать | CVE-2006-1598Эксплойта нет | AN HTTPD 1.42n, and possibly other versions before 1.42p, allows remote attackers to obtain source code of scripts via crafted requests withan · an-httpd | Высокая7,8 | — | 1,9 % | 3 апр. 2006 г. |
31Наблюдать | CVE-1999-0947Proof of concept | AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via an · an-httpd | Высокая7,5 | — | 3,2 % | 2 нояб. 1999 г. |
27Наблюдать | CVE-2005-1086Proof of concept | Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request withan · an-httpd | Средняя6,4 | — | 5,6 % | 2 мая 2005 г. |
26Наблюдать | CVE-2005-1087Proof of concept | CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfian · an-httpd | Средняя6,4 | — | 2,3 % | 7 апр. 2005 г. |
21Наблюдать | CVE-2003-1269Эксплойта нет | AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks tan · an-http | Средняя5,0 | — | 2,1 % | 31 дек. 2003 г. |
20Наблюдать | CVE-2003-1270Эксплойта нет | AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possiban · an-http | Средняя5,0 | — | 1,4 % | 31 дек. 2003 г. |
18Наблюдать | CVE-2003-1271Proof of concept | Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users viaan · an-http | Средняя4,3 | — | 1,8 % | 31 дек. 2003 г. |
- CVE-2002-193032Наблюдать
Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username.
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %an · an-httpd31 дек. 2002 г.
- CVE-2006-159832Наблюдать
AN HTTPD 1.42n, and possibly other versions before 1.42p, allows remote attackers to obtain source code of scripts via crafted requests with
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %an · an-httpd3 апр. 2006 г.
- CVE-1999-094731Наблюдать
AN-HTTPd provides example CGI scripts test.bat, input.bat, input2.bat, and envout.bat, which allow remote attackers to execute commands via
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %an · an-httpd2 нояб. 1999 г.
- CVE-2005-108627Наблюдать
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with
СредняяCVSS 6,4Proof of conceptEPSS 6 %an · an-httpd2 мая 2005 г.
- CVE-2005-108726Наблюдать
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfi
СредняяCVSS 6,4Proof of conceptEPSS 2 %an · an-httpd7 апр. 2005 г.
- CVE-2003-126921Наблюдать
AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks t
СредняяCVSS 5,0Эксплойта нетEPSS 2 %an · an-http31 дек. 2003 г.
- CVE-2003-127020Наблюдать
AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possib
СредняяCVSS 5,0Эксплойта нетEPSS 1 %an · an-http31 дек. 2003 г.
- CVE-2003-127118Наблюдать
Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via
СредняяCVSS 4,3Proof of conceptEPSS 2 %an · an-http31 дек. 2003 г.