Записи webdav
5 опубликованных записей вендора webdav.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-134 Use of Externally-Controlled Format String1
- CWE-326 Inadequate Encryption Strength1
- CWE-399 Resource Management Errors1
- CWE-787 Out-of-bounds Write1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2004-0398Эксплойта нет | Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadavwebdav · cadaver · CWE-787 | Высокая7,5 | — | 5,0 % | 7 июл. 2004 г. |
30Наблюдать | CVE-2004-0179Proof of concept | Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversiowebdav · neon · CWE-134 | Средняя6,8 | — | 11,1 % | 1 июн. 2004 г. |
23Наблюдать | CVE-2009-2474Эксплойта нет | neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name webdav · neon · CWE-326 | Средняя5,8 | — | 1,5 % | 21 авг. 2009 г. |
20Наблюдать | CVE-2009-2473Proof of concept | neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackerswebdav · neon · CWE-399 | Средняя4,3 | — | 8,4 % | 21 авг. 2009 г. |
18Наблюдать | CVE-2008-3746Эксплойта нет | neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Diwebdav · neon | Средняя4,3 | — | 2,3 % | 27 авг. 2008 г. |
- CVE-2004-039832Наблюдать
Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadav
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %webdav · cadaver7 июл. 2004 г.
- CVE-2004-017930Наблюдать
Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversio
СредняяCVSS 6,8Proof of conceptEPSS 11 %webdav · neon1 июн. 2004 г.
- CVE-2009-247423Наблюдать
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name
СредняяCVSS 5,8Эксплойта нетEPSS 1 %webdav · neon21 авг. 2009 г.
- CVE-2009-247320Наблюдать
neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers
СредняяCVSS 4,3Proof of conceptEPSS 8 %webdav · neon21 авг. 2009 г.
- CVE-2008-374618Наблюдать
neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Di
СредняяCVSS 4,3Эксплойта нетEPSS 2 %webdav · neon27 авг. 2008 г.