Записи crowcpp
6 опубликованных записей вендора crowcpp.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')1
- CWE-193 Off-by-one Error1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-416 Use After Free1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-908 Use of Uninitialized Resource1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-34970Proof of concept | Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.crowcpp · crow · CWE-193 | Критическая9,8 | — | 4,0 % | 4 авг. 2022 г. |
40В плане | CVE-2022-38667Эксплойта нет | HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used.crowcpp · crow · CWE-416 | Критическая9,8 | — | 2,9 % | 22 авг. 2022 г. |
30Наблюдать | CVE-2021-23514Эксплойта нет | This affects the package Crow before 0.3+4.crowcpp · crow · CWE-22 | Высокая7,5 | — | 1,6 % | 13 янв. 2022 г. |
30Наблюдать | CVE-2022-38668Эксплойта нет | HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfillincrowcpp · crow · CWE-908 | Высокая7,5 | — | 1,4 % | 22 авг. 2022 г. |
24Наблюдать | CVE-2021-23824Эксплойта нет | This affects the package Crow before 0.3+4.crowcpp · crow · CWE-79 | Средняя6,1 | — | 0,9 % | 13 янв. 2022 г. |
24Наблюдать | CVE-2023-26142Эксплойта нет | All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values.crowcpp · crow · CWE-113 | Средняя6,1 | — | 0,5 % | 12 сент. 2023 г. |
- CVE-2022-3497040В плане
Crow before 1.0+4 has a heap-based buffer overflow via the function qs_parse in query_string.h.
КритическаяCVSS 9,8Proof of conceptEPSS 4 %crowcpp · crow4 авг. 2022 г.
- CVE-2022-3866740В плане
HTTP applications (servers) based on Crow through 1.0+4 may allow a Use-After-Free and code execution when HTTP pipelining is used.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %crowcpp · crow22 авг. 2022 г.
- CVE-2021-2351430Наблюдать
This affects the package Crow before 0.3+4.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %crowcpp · crow13 янв. 2022 г.
- CVE-2022-3866830Наблюдать
HTTP applications (servers) based on Crow through 1.0+4 may reveal potentially sensitive uninitialized data from stack memory when fulfillin
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %crowcpp · crow22 авг. 2022 г.
- CVE-2021-2382424Наблюдать
This affects the package Crow before 0.3+4.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %crowcpp · crow13 янв. 2022 г.
- CVE-2023-2614224Наблюдать
All versions of the package crow are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %crowcpp · crow12 сент. 2023 г.