Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.131349
Kategorie:Web Servers
Titel:Cesanta Mongoose Web Server 7.14 Multiple Vulnerabilities
Zusammenfassung:Cesanta Mongoose Web Server is prone to multiple; vulnerabilities.
Beschreibung:Summary:
Cesanta Mongoose Web Server is prone to multiple
vulnerabilities.

Vulnerability Insight:
The following vulnerabilities exist:

- CVE-2024-42383: Cesanta Mongoose Web Server allows to write a NULL byte value beyond the memory
space dedicated for the hostname field.

- CVE-2024-42384, CVE-2024-42386: Cesanta Mongoose Web Server allows an attacker to send an
unexpected TLS packet and produce a segmentation fault on the application.

- CVE-2024-42385: Cesanta Mongoose Web Server allows to trigger an out-of-bound memory write if
the PEM certificate contains unexpected characters.

- CVE-2024-42387, CVE-2024-42388, CVE-2024-42389, CVE-2024-42390, CVE-2024-42391: Cesanta
Mongoose Web Server allows an attacker to send an unexpected TLS packet and force the application
to read unintended heap memory space.

- CVE-2024-42392: Cesanta Mongoose Web Server allows to trigger an infinite loop bug if the input
string contains unexpected characters.

Affected Software/OS:
Mongoose Web Server probably version 7.14 only.

Solution:
No known solution is available as of 04th December, 2024.
Information regarding this issue will be updated once solution details are available.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2024-42383
Common Vulnerability Exposure (CVE) ID: CVE-2024-42384
Common Vulnerability Exposure (CVE) ID: CVE-2024-42385
Common Vulnerability Exposure (CVE) ID: CVE-2024-42386
Common Vulnerability Exposure (CVE) ID: CVE-2024-42387
Common Vulnerability Exposure (CVE) ID: CVE-2024-42388
Common Vulnerability Exposure (CVE) ID: CVE-2024-42389
Common Vulnerability Exposure (CVE) ID: CVE-2024-42390
Common Vulnerability Exposure (CVE) ID: CVE-2024-42391
Common Vulnerability Exposure (CVE) ID: CVE-2024-42392
CopyrightCopyright (C) 2024 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.