Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2018-1000518

Disclosure Date: June 26, 2018 (last updated November 26, 2024)
aaugustin websockets version 4 contains a CWE-409: Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Servers and clients, unless configured with compression=None that can result in Denial of Service by memory exhaustion. This attack appear to be exploitable via Sending a specially crafted frame on an established connection. This vulnerability appears to have been fixed in 5.
Attacker Value
Unknown

CVE-2017-16107

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
pooledwebsocket is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown

CVE-2014-6309

Disclosure Date: April 12, 2018 (last updated November 26, 2024)
The HTTP and WebSocket engine components in the server in Kaazing Gateway 4.0.2, 4.0.3, and 4.0.4 and Gateway - JMS Edition 4.0.2, 4.0.3, and 4.0.4 allow remote attackers to obtain sensitive information via vectors related to HTTP request handling.
Attacker Value
Unknown

CVE-2017-6910

Disclosure Date: April 12, 2018 (last updated November 26, 2024)
The HTTP and WebSocket engine components in the server in Kaazing Gateway before 4.5.3 hotfix-1, Gateway - JMS Edition before 4.0.5 hotfix-15, 4.0.6 before hotfix-4, 4.0.7, 4.0.9 before hotfix-19, 4.4.x before 4.4.2 hotfix-1, 4.5.x before 4.5.3 hotfix-1, and Gateway Community and Enterprise Editions before 5.6.0 allow remote attackers to bypass intended access restrictions and obtain sensitive information via vectors related to HTTP request handling.
0
Attacker Value
Unknown

CVE-2017-1000209

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS servers via an arbitrary valid certificate.
0
Attacker Value
Unknown

CVE-2017-0249

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
An elevation of privilege vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
0
Attacker Value
Unknown

CVE-2017-0256

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
A spoofing vulnerability exists when the ASP.NET Core fails to properly sanitize web requests.
0
Attacker Value
Unknown

CVE-2017-0247

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
A denial of service vulnerability exists when the ASP.NET Core fails to properly validate web requests. NOTE: Microsoft has not commented on third-party claims that the issue is that the TextEncoder.EncodeCore function in the System.Text.Encodings.Web package in ASP.NET Core Mvc before 1.0.4 and 1.1.x before 1.1.3 allows remote attackers to cause a denial of service by leveraging failure to properly calculate the length of 4-byte characters in the Unicode Non-Character range.
0