5

CVE-2007-2197

Race condition in the NeatUpload ASP.NET component 1.2.11 through 1.2.16, 1.1.18 through 1.1.23, and trunk.379 through trunk.445 allows remote attackers to obtain other clients' HTTP responses via multiple simultaneous requests, which triggers multiple calls to HttpWorkerRequest.FlushResponse for the same HttpWorkerRequest object and causes a buffer to be reused for a different request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Brettle DevelopmentNeatupload Version1.1.18
Brettle DevelopmentNeatupload Version1.1.19
Brettle DevelopmentNeatupload Version1.1.20
Brettle DevelopmentNeatupload Version1.1.21
Brettle DevelopmentNeatupload Version1.1.22
Brettle DevelopmentNeatupload Version1.1.23
Brettle DevelopmentNeatupload Version1.2.11
Brettle DevelopmentNeatupload Version1.2.12
Brettle DevelopmentNeatupload Version1.2.13
Brettle DevelopmentNeatupload Version1.2.14
Brettle DevelopmentNeatupload Version1.2.15
Brettle DevelopmentNeatupload Version1.2.16
Brettle DevelopmentNeatupload Versiontrunk.379
Brettle DevelopmentNeatupload Versiontrunk.380
Brettle DevelopmentNeatupload Versiontrunk.381
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.22% 0.647
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/25003
Vendor Advisory
http://www.securityfocus.com/archive/1/466404/100/0/threaded
http://www.securityfocus.com/bid/23578
https://exchange.xforce.ibmcloud.com/vulnerabilities/33785