Записи yaws
11 опубликованных записей вендора yaws.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 9,1 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 81,8 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-326 Inadequate Encryption Strength1
- CWE-399 Resource Management Errors1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
11 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
54В плане | CVE-2017-10974Proof of concept | Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.yaws · yaws · CWE-22 | Высокая7,5 | — | 81,2 % | 7 июл. 2017 г. |
44В плане | CVE-2020-24916Эксплойта нет | CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.yaws · yaws · CWE-78 | Критическая9,8 | — | 17,4 % | 9 сент. 2020 г. |
40В плане | CVE-2020-24379Эксплойта нет | WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.yaws · yaws · CWE-611 | Критическая9,8 | — | 3,4 % | 9 сент. 2020 г. |
31Наблюдать | CVE-2011-4350Готовый эксплойт | Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed.yaws · yaws · CWE-22 | Средняя6,5 | — | 16,1 % | 26 нояб. 2019 г. |
24Наблюдать | CVE-2016-1000108Эксплойта нет | yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications fryaws · yaws · CWE-601 | Средняя6,1 | — | 1,1 % | 10 дек. 2019 г. |
23Наблюдать | CVE-2009-0751Proof of concept | Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of heyaws · yaws · CWE-399 | Средняя5,0 | — | 10,4 % | 2 мар. 2009 г. |
23Наблюдать | CVE-2009-4495Proof of concept | Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's tityaws · yaws · CWE-20 | Средняя5,0 | — | 9,0 % | 13 янв. 2010 г. |
23Наблюдать | CVE-2010-4181Proof of concept | Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequencyaws · yaws · CWE-22 | Средняя5,0 | — | 8,5 % | 4 нояб. 2010 г. |
22Наблюдать | CVE-2020-12872Эксплойта нет | yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if runninyaws · yaws · CWE-326 | Средняя5,5 | — | 0,4 % | 15 мая 2020 г. |
20Наблюдать | CVE-2005-2008Эксплойта нет | Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a traiyaws · webserver | Средняя5,0 | — | 1,5 % | 17 июн. 2005 г. |
18Наблюдать | CVE-2011-5025Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web scriyaws · yaws · CWE-79 | Средняя4,3 | — | 2,7 % | 29 дек. 2011 г. |
- CVE-2017-1097454В плане
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.
ВысокаяCVSS 7,5Proof of conceptEPSS 81 %yaws · yaws7 июл. 2017 г.
- CVE-2020-2491644В плане
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 17 %yaws · yaws9 сент. 2020 г.
- CVE-2020-2437940В плане
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %yaws · yaws9 сент. 2020 г.
- CVE-2011-435031Наблюдать
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed.
СредняяCVSS 6,5Готовый эксплойтEPSS 16 %yaws · yaws26 нояб. 2019 г.
- CVE-2016-100010824Наблюдать
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications fr
СредняяCVSS 6,1Эксплойта нетEPSS 1 %yaws · yaws10 дек. 2019 г.
- CVE-2009-075123Наблюдать
Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of he
СредняяCVSS 5,0Proof of conceptEPSS 10 %yaws · yaws2 мар. 2009 г.
- CVE-2009-449523Наблюдать
Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's tit
СредняяCVSS 5,0Proof of conceptEPSS 9 %yaws · yaws13 янв. 2010 г.
- CVE-2010-418123Наблюдать
Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequenc
СредняяCVSS 5,0Proof of conceptEPSS 8 %yaws · yaws4 нояб. 2010 г.
- CVE-2020-1287222Наблюдать
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if runnin
СредняяCVSS 5,5Эксплойта нетEPSS 0 %yaws · yaws15 мая 2020 г.
- CVE-2005-200820Наблюдать
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trai
СредняяCVSS 5,0Эксплойта нетEPSS 1 %yaws · webserver17 июн. 2005 г.
- CVE-2011-502518Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web scri
СредняяCVSS 4,3Proof of conceptEPSS 3 %yaws · yaws29 дек. 2011 г.