boa kayıtları
boa üreticisine ait 12 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %8,3
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %8,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-772 Missing Release of Resource after Effective Lifetime1
- CWE-863 Incorrect Authorization1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-248 Uncaught Exception1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
12 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
60Bu hafta | CVE-2007-4915Silahlaştırılmış | The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from enteboa · boa webserver · CWE-20 | Kritik10,0 | — | %68,2 | 17 Eyl 2007 |
51Planlayın | CVE-2017-9833Kavram kanıtı | /cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privboa · boa · CWE-22 | Yüksek7,5 | — | %68,5 | 23 Haz 2017 |
40Planlayın | CVE-2018-21027İstismar yok | Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.boa · boa · CWE-119 | Kritik9,8 | — | %2,4 | 11 Eki 2019 |
39İzleyin | CVE-2022-44117İstismar yok | Boa 0.94.14rc21 is vulnerable to SQL Injection via username.boa · boa · CWE-89 | Kritik9,8 | — | %0,7 | 23 Kas 2022 |
34İzleyin | CVE-2021-33558Kavram kanıtı | Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, lboa · boa | Yüksek7,5 | — | %12,3 | 27 May 2021 |
31İzleyin | CVE-2018-21028İstismar yok | Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.boa · boa · CWE-772 | Yüksek7,5 | — | %2,1 | 11 Eki 2019 |
30İzleyin | CVE-2016-9564İstismar yok | Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with boa · boa · CWE-20 | Yüksek7,5 | — | %1,4 | 30 Kas 2016 |
30İzleyin | CVE-2024-43367İstismar yok | Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objectsboa-dev · boa · CWE-248 | Yüksek7,5 | — | %0,6 | 15 Ağu 2024 |
30İzleyin | CVE-2024-47916İstismar yok | Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')boa web server · boa web server 0.94.14rc21 · CWE-22 | Yüksek7,5 | — | %0,5 | 14 Kas 2024 |
24İzleyin | CVE-2009-4496Kavram kanıtı | Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a windowboa · boa · CWE-20 | Orta5,0 | — | %12,3 | 13 Oca 2010 |
23İzleyin | CVE-2000-0920Kavram kanıtı | Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified ..boa · boa webserver | Orta5,0 | — | %8,4 | 19 Ara 2000 |
21İzleyin | CVE-2022-45956İstismar yok | Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone tboa · boa · CWE-863 | Orta5,3 | — | %0,8 | 12 Ara 2022 |
- CVE-2007-491560Bu hafta
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from ente
KritikCVSS 10,0SilahlaştırılmışEPSS %68boa · boa webserver17 Eyl 2007
- CVE-2017-983351Planlayın
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root priv
YüksekCVSS 7,5Kavram kanıtıEPSS %68boa · boa23 Haz 2017
- CVE-2018-2102740Planlayın
Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.
KritikCVSS 9,8İstismar yokEPSS %2boa · boa11 Eki 2019
- CVE-2022-4411739İzleyin
Boa 0.94.14rc21 is vulnerable to SQL Injection via username.
KritikCVSS 9,8İstismar yokEPSS %1boa · boa23 Kas 2022
- CVE-2021-3355834İzleyin
Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, l
YüksekCVSS 7,5Kavram kanıtıEPSS %12boa · boa27 May 2021
- CVE-2018-2102831İzleyin
Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.
YüksekCVSS 7,5İstismar yokEPSS %2boa · boa11 Eki 2019
- CVE-2016-956430İzleyin
Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with
YüksekCVSS 7,5İstismar yokEPSS %1boa · boa30 Kas 2016
- CVE-2024-4336730İzleyin
Boa has an uncaught exception when transitioning the state of `AsyncGenerator` objects
YüksekCVSS 7,5İstismar yokEPSS %1boa-dev · boa15 Ağu 2024
- CVE-2024-4791630İzleyin
Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
YüksekCVSS 7,5İstismar yokEPSS %1boa web server · boa web server 0.94.14rc2114 Kas 2024
- CVE-2009-449624İzleyin
Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window
OrtaCVSS 5,0Kavram kanıtıEPSS %12boa · boa13 Oca 2010
- CVE-2000-092023İzleyin
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified ..
OrtaCVSS 5,0Kavram kanıtıEPSS %8boa · boa webserver19 Ara 2000
- CVE-2022-4595621İzleyin
Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone t
OrtaCVSS 5,3İstismar yokEPSS %1boa · boa12 Ara 2022