Vulnerabilities > Frank Yaul > Corehttp

DATE CVE VULNERABILITY TITLE RISK
2009-12-08 CVE-2009-3586 Numeric Errors vulnerability in Frank Yaul Corehttp 0.5.3.1
Off-by-one error in src/http.c in CoreHTTP 0.5.3.1 and earlier allows remote attackers to cause a denial of service or possibly execute arbitrary code via an HTTP request with a long first line that triggers a buffer overflow.
network
low complexity
frank-yaul CWE-189
7.5
2007-07-30 CVE-2007-4060 Buffer Overflow vulnerability in Frank Yaul Corehttp 0.5.3Alpha
Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attackers to execute arbitrary code via a long string in the (1) method name or (2) URI in an HTTP request.
network
low complexity
frank-yaul
critical
9.0