|
313691
|
9.8 |
CRITICAL
Network
|
acme
|
thttpd
|
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
|
CWE-193
Off-by-one Error
|
CVE-2001-1496
|
2024-02-8 11:19 |
2001-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313692
|
9.8 |
CRITICAL
Network
|
mbedthis
|
appweb_http_server
|
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions via a URI with mixed case characters.
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2004-2214
|
2024-02-8 11:12 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313693
|
9.8 |
CRITICAL
Network
|
novell
|
edirectory
|
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote attackers to conduct brute force password guessing.
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2002-2119
|
2024-02-8 11:12 |
2002-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313694
|
7.5 |
HIGH
Network
|
apple
|
quicktime_streaming_server darwin_streaming_server mac_os_x_server mac_os_x
|
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attack…
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2004-1083
|
2024-02-8 11:09 |
2004-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313695
|
- |
|
-
|
-
|
Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
|
-
|
CVE-2024-22984
|
2024-02-8 05:15 |
2024-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313696
|
- |
|
cisco
|
ios
|
AAA authentication on Cisco systems allows attackers to execute commands without authorization.
|
NVD-CWE-Other
|
CVE-1999-0293
|
2024-02-8 03:06 |
1998-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313697
|
- |
|
-
|
-
|
Rejected reason: We have rejected this CVE as it was determined a non-security issue by the vendor.
|
-
|
CVE-2023-5584
|
2024-02-7 00:15 |
2024-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313698
|
- |
|
postgresql
|
postgresql
|
The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays.
|
NVD-CWE-Other
|
CVE-2005-0246
|
2024-02-6 04:56 |
2005-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313699
|
- |
|
-
|
-
|
Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2023.
|
-
|
CVE-2023-47170
|
2024-02-5 14:15 |
2024-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313700
|
9.8 |
CRITICAL
Network
|
pingtel
|
xpressa_firmware
|
Pingtel xpressa SIP-based voice-over-IP phone 1.2.5 through 1.2.7.4 downloads phone applications from a web site but can not verify the integrity of the applications, which could allow remote attacke…
|
CWE-494
Download of Code Without Integrity Check
|
CVE-2002-0671
|
2024-02-3 11:32 |
2002-07-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|