Show filters
52 Total Results
Displaying 41-50 of 52
Sort by:
Attacker Value
Unknown

CVE-2017-2922

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause a buffer to be allocated while leaving stale pointers which leads to a use-after-free vulnerability which can be exploited to achieve remote code execution. An attacker needs to send a specially crafted websocket packet over the network to trigger this vulnerability.
Attacker Value
Unknown

CVE-2017-2921

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
An exploitable memory corruption vulnerability exists in the Websocket protocol implementation of Cesanta Mongoose 6.8. A specially crafted websocket packet can cause an integer overflow, leading to a heap buffer overflow and resulting in denial of service and potential remote code execution. An attacker needs to send a specially crafted websocket packet over network to trigger this vulnerability.
Attacker Value
Unknown

CVE-2017-2892

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT packet can cause an arbitrary out-of-bounds memory read and write potentially resulting in information disclosure, denial of service and remote code execution. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.
Attacker Value
Unknown

CVE-2017-2895

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
An exploitable arbitrary memory read vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory read potentially resulting in information disclosure and denial of service. An attacker needs to send a specially crafted MQTT packet over the network to trigger this vulnerability.
Attacker Value
Unknown

CVE-2017-2909

Disclosure Date: November 07, 2017 (last updated November 26, 2024)
An infinite loop programming error exists in the DNS server functionality of Cesanta Mongoose 6.8 library. A specially crafted DNS request can cause an infinite loop resulting in high CPU usage and Denial Of Service. An attacker can send a packet over the network to trigger this vulnerability.
Attacker Value
Unknown

CVE-2017-11567

Disclosure Date: September 07, 2017 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to execute arbitrary code remotely.
0
Attacker Value
Unknown

CVE-2017-7185

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary string.
0
Attacker Value
Unknown

CVE-2014-2829

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an "xmppbomb" attack.
0
Attacker Value
Unknown

CVE-2011-2900

Disclosure Date: August 05, 2011 (last updated October 04, 2023)
Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as exploited in the wild in 2011.
0
Attacker Value
Unknown

CVE-2009-4535

Disclosure Date: December 31, 2009 (last updated October 04, 2023)
Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.
0