Skip to main content

Vendor/product archive

t._hauck / jana_web_server CVEs

Beta · best-effort

10 CVEs tagged to t._hauck / jana_web_server0 Critical, 4 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2002-1061

Published Oct 4, 2002

Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service and possibly execute arbitrary…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1062

Published Oct 4, 2002

Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1063

Published Oct 4, 2002

Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of FTP PASV reques…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1064

Published Oct 4, 2002

Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid u…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1065

Published Oct 4, 2002

Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-1066

Published Oct 4, 2002

Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR o…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-0557

Published Aug 14, 2001

T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2001-0558

Published Aug 14, 2001

T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-1082

Published Oct 8, 1999

Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.

CVSS 5.0 · Medium
Buzz score
4.0
OTX pulse activity
Vendor/product tagsBeta · best-effort

CVE-1999-1083

Published Oct 8, 1999

Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1