Vulnerabilities > Bigantsoft > Bigant IM Message Server

DATE CVE VULNERABILITY TITLE RISK
2013-02-24 CVE-2012-6275 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Bigantsoft Bigant IM Message Server
Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request.
network
low complexity
bigantsoft CWE-119
critical
10.0
2013-02-24 CVE-2012-6274 Improper Authentication vulnerability in Bigantsoft Bigant IM Message Server
BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors.
network
low complexity
bigantsoft CWE-287
5.0
2013-02-24 CVE-2012-6273 SQL Injection vulnerability in Bigantsoft Bigant IM Message Server
SQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search user) request.
network
low complexity
bigantsoft CWE-89
7.5