5

CVE-2005-2806

Exploit
client.cpp in BNBT EasyTracker 7.7r3.2004.10.27 and earlier allows remote attackers to cause a denial of service (application hang) via an HTTP header containing only a ":" (colon), possibly leading to an integer signedness error due to a missing field name or value.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trevor HoganBnbt Version7.5_beta_release2
Trevor HoganBnbt Version7.5_beta_release3
Trevor HoganBnbt Version7.7_2004-10-27_r3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.7% 0.742
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://marc.info/?l=bugtraq&m=112542080127451&w=2
http://secunia.com/advisories/16613/
http://secway.org/advisory/AD20050830.txt
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/14700
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/22058