Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Boa MEDIUM 5.3
CVE-2022-45956

Boa Web Server versions 0.94.13 through 0.94.14 fail to validate the correct security constraint on the HEAD HTTP method allowing everyone to bypass …

No fix yet
Fix from $1,600 2022-12-12
Boa CRITICAL 9.8
CVE-2022-44117

Boa 0.94.14rc21 is vulnerable to SQL Injection via username. NOTE: the is disputed by multiple third parties because Boa does not ship with any suppo…

No fix yet
Fix from $2,300 2022-11-23
Boa HIGH 7.5
CVE-2021-33558EPSS 12%

Boa 0.94.13 allows remote attackers to obtain sensitive information via a misconfiguration involving backup.html, preview.html, js/log.js, log.html, …

No fix yet
Fix from $1,950 2021-05-27
Boa CRITICAL 9.8
CVE-2018-21027

Boa through 0.94.14rc21 allows remote attackers to trigger an out-of-memory (OOM) condition because malloc is mishandled.

Fix: after 0.94.14.21
Fix from $2,300 2019-10-11
Boa HIGH 7.5
CVE-2018-21028

Boa through 0.94.14rc21 allows remote attackers to trigger a memory leak because of missing calls to the free function.

Fix: after 0.94.14.21
Fix from $1,950 2019-10-11
Boa HIGH 7.5
CVE-2017-9833EPSS 68%

/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read files with root privileges. N…

No fix yet
Fix from $1,950 2017-06-24
Boa HIGH 7.5
CVE-2016-9564

Buffer overflow in send_redirect() in Boa Webserver 0.92r allows remote attackers to DoS via an HTTP GET request requesting a long URI with only '/' …

No fix yet
Fix from $1,950 2016-11-30
Boa MEDIUM 5.0
CVE-2009-4496EPSS 12%

Boa 0.94.14rc21 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title,…

No fix yet
Fix from $1,600 2010-01-13
Boa Webserver HIGH 10.0
CVE-2007-4915EPSS 68%

The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent stack writes from entering memo…

No fix yet
Fix from $1,950 2007-09-17
Boa Webserver MEDIUM 5.0
CVE-2000-0920EPSS 8%

Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) …

Fix: after 0.94.8.2
Fix from $1,600 2000-12-19