Lucene search

K
cve[email protected]CVE-2005-1666
HistoryMay 18, 2005 - 4:00 a.m.

CVE-2005-1666

2005-05-1804:00:00
web.nvd.nist.gov
21
cve-2005-1666
buffer overflow
orenosv
http
ftp
server
denial of service
remote code execution
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.2 High

AI Score

Confidence

High

0.058 Low

EPSS

Percentile

93.4%

Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service (server crash) and possibly execute arbitrary code via long arguments to FTP commands such as MKD, RMD, or DELE, which are processed by the (1) ftp_xlate_path, (2) ftp_is_canonical, or (3) os_fn_nativize functions, or (4) a long SSI command that is processed by the parse_cmd function in cgissi.exe.

Affected configurations

NVD
Node
orenosvorenosv_http_ftp_serverRange0.8.1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.2 High

AI Score

Confidence

High

0.058 Low

EPSS

Percentile

93.4%

Related for CVE-2005-1666