5

CVE-2007-2197

Race condition in the NeatUpload ASP.NET component 1.2.11 through 1.2.16, 1.1.18 through 1.1.23, and trunk.379 through trunk.445 allows remote attackers to obtain other clients' HTTP responses via multiple simultaneous requests, which triggers multiple calls to HttpWorkerRequest.FlushResponse for the same HttpWorkerRequest object and causes a buffer to be reused for a different request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Brettle DevelopmentNeatupload Version1.1.18
Brettle DevelopmentNeatupload Version1.1.19
Brettle DevelopmentNeatupload Version1.1.20
Brettle DevelopmentNeatupload Version1.1.21
Brettle DevelopmentNeatupload Version1.1.22
Brettle DevelopmentNeatupload Version1.1.23
Brettle DevelopmentNeatupload Version1.2.11
Brettle DevelopmentNeatupload Version1.2.12
Brettle DevelopmentNeatupload Version1.2.13
Brettle DevelopmentNeatupload Version1.2.14
Brettle DevelopmentNeatupload Version1.2.15
Brettle DevelopmentNeatupload Version1.2.16
Brettle DevelopmentNeatupload Versiontrunk.379
Brettle DevelopmentNeatupload Versiontrunk.380
Brettle DevelopmentNeatupload Versiontrunk.381
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.593
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.