Перейти к содержимому
Noroxi

Записи yaws

11 опубликованных записей вендора yaws.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 9,1 %
Pre-auth RCE
2
С записью об исправлении
81,8 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

11 записей
  • CVE-2017-10974
    54В плане

    Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.

    ВысокаяCVSS 7,5Proof of conceptEPSS 81 %

    yaws · yaws7 июл. 2017 г.

  • CVE-2020-24916
    44В плане

    CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.

    КритическаяCVSS 9,8Эксплойта нетEPSS 17 %

    yaws · yaws9 сент. 2020 г.

  • CVE-2020-24379
    40В плане

    WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    yaws · yaws9 сент. 2020 г.

  • CVE-2011-4350
    31Наблюдать

    Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed.

    СредняяCVSS 6,5Готовый эксплойтEPSS 16 %

    yaws · yaws26 нояб. 2019 г.

  • CVE-2016-1000108
    24Наблюдать

    yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications fr

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    yaws · yaws10 дек. 2019 г.

  • CVE-2009-0751
    23Наблюдать

    Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of he

    СредняяCVSS 5,0Proof of conceptEPSS 10 %

    yaws · yaws2 мар. 2009 г.

  • CVE-2009-4495
    23Наблюдать

    Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's tit

    СредняяCVSS 5,0Proof of conceptEPSS 9 %

    yaws · yaws13 янв. 2010 г.

  • CVE-2010-4181
    23Наблюдать

    Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequenc

    СредняяCVSS 5,0Proof of conceptEPSS 8 %

    yaws · yaws4 нояб. 2010 г.

  • CVE-2020-12872
    22Наблюдать

    yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if runnin

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    yaws · yaws15 мая 2020 г.

  • CVE-2005-2008
    20Наблюдать

    Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trai

    СредняяCVSS 5,0Эксплойта нетEPSS 1 %

    yaws · webserver17 июн. 2005 г.

  • CVE-2011-5025
    18Наблюдать

    Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web scri

    СредняяCVSS 4,3Proof of conceptEPSS 3 %

    yaws · yaws29 дек. 2011 г.