T Hauck Jana Web Server vulnerabilities
10 known vulnerabilities affecting t_hauck/jana_web_server.
Total CVEs
10
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2001-0557P4MEDIUMCVSS 5.0PoC≤ 1.46v1.0j+2 more2001-08-14
CVE-2001-0557 [MEDIUM] CVE-2001-0557: T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..'
T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).
nvd
CVE-1999-1082P4MEDIUMCVSS 5.0PoCv1.0v1.40+2 more1999-10-08
CVE-1999-1082 [MEDIUM] CVE-1999-1082: Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arb
Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack.
nvd
CVE-1999-1083P4MEDIUMCVSS 5.0PoCv1.0v1.45+1 more1999-10-08
CVE-1999-1083 [MEDIUM] CVE-1999-1083: Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arb
Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack.
nvd
CVE-2001-0558P4MEDIUMCVSS 5.0PoCv1.45v1.46+2 more2001-08-14
CVE-2001-0558 [MEDIUM] CVE-2001-0558: T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of servi
T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0).
nvd
CVE-2002-1062P4HIGHCVSS 7.5v1.0v1.45+5 more2002-10-04
CVE-2002-1062 [HIGH] CVE-2002-1062: Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote
Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.
nvd
CVE-2002-1061P4HIGHCVSS 7.5v1.0v1.45+5 more2002-10-04
CVE-2002-1061 [HIGH] CVE-2002-1061: Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allo
Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) an HTTP GET request with a long major version number, (2) an HTTP GET request to the HTTP proxy on port 3128 with a long major version number, (3) a long OK reply from a P
nvd
CVE-2002-1066P4HIGHCVSS 7.5v1.0v1.45+5 more2002-10-04
CVE-2002-1066 [HIGH] CVE-2002-1066: Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and
Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or (2) DELE command to the POP3 server, which exceeds the array limits and allows a buffer overflow attack.
nvd
CVE-2002-1065P4HIGHCVSS 7.5v1.0v1.45+5 more2002-10-04
CVE-2002-1065 [HIGH] CVE-2002-1065: Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of u
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain privileges via brute force username and password guessing.
nvd
CVE-2002-1064P4MEDIUMCVSS 5.0v1.0v1.45+5 more2002-10-04
CVE-2002-1064 [MEDIUM] CVE-2002-1064: Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid users on the server.
nvd
CVE-2002-1063P4MEDIUMCVSS 5.0v1.0v1.45+5 more2002-10-04
CVE-2002-1063 [MEDIUM] CVE-2002-1063: Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause
Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of FTP PASV requests, which consumes all available FTP ports.
nvd