Show filters
871 Total Results
Displaying 301-310 of 871
Sort by:
Attacker Value
Unknown
CVE-2020-2545
Disclosure Date: January 15, 2020 (last updated November 27, 2024)
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OSSL Module). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HTTP Server. CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).
0
Attacker Value
Unknown
CVE-2020-2530
Disclosure Date: January 15, 2020 (last updated November 27, 2024)
Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle HTTP Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HTTP Server accessible data as well as unauthorized read access to a subset of Oracle HTTP Server accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
0
Attacker Value
Unknown
CVE-2019-20138
Disclosure Date: December 30, 2019 (last updated November 27, 2024)
The HTTP Authentication library before 2019-12-27 for Nim has weak password hashing because the default algorithm for libsodium's crypto_pwhash_str is not used.
0
Attacker Value
Unknown
CVE-2007-0158
Disclosure Date: December 27, 2019 (last updated November 27, 2024)
thttpd 2007 has buffer underflow.
0
Attacker Value
Unknown
CVE-2013-4743
Disclosure Date: December 27, 2019 (last updated November 27, 2024)
Static HTTP Server 1.0 has a Local Overflow
0
Attacker Value
Unknown
CVE-2019-15600
Disclosure Date: December 18, 2019 (last updated November 27, 2024)
A Path traversal exists in http_server which allows an attacker to read arbitrary system files.
0
Attacker Value
Unknown
CVE-2012-5640
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files
0
Attacker Value
Unknown
CVE-2019-10219
Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
0
Attacker Value
Unknown
CVE-2019-16279
Disclosure Date: October 14, 2019 (last updated November 27, 2024)
A memory error in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2019-16278
Disclosure Date: October 14, 2019 (last updated November 08, 2024)
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a crafted HTTP request.
0