5
CVE-2007-2197
- EPSS 0.39%
- Veröffentlicht 24.04.2007 17:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Race condition in the NeatUpload ASP.NET component 1.2.11 through 1.2.16, 1.1.18 through 1.1.23, and trunk.379 through trunk.445 allows remote attackers to obtain other clients' HTTP responses via multiple simultaneous requests, which triggers multiple calls to HttpWorkerRequest.FlushResponse for the same HttpWorkerRequest object and causes a buffer to be reused for a different request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Brettle Development ≫ Neatupload Version1.1.18
Brettle Development ≫ Neatupload Version1.1.19
Brettle Development ≫ Neatupload Version1.1.20
Brettle Development ≫ Neatupload Version1.1.21
Brettle Development ≫ Neatupload Version1.1.22
Brettle Development ≫ Neatupload Version1.1.23
Brettle Development ≫ Neatupload Version1.2.11
Brettle Development ≫ Neatupload Version1.2.12
Brettle Development ≫ Neatupload Version1.2.13
Brettle Development ≫ Neatupload Version1.2.14
Brettle Development ≫ Neatupload Version1.2.15
Brettle Development ≫ Neatupload Version1.2.16
Brettle Development ≫ Neatupload Versiontrunk.379
Brettle Development ≫ Neatupload Versiontrunk.380
Brettle Development ≫ Neatupload Versiontrunk.381
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.593 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|