5
CVSSv2

CVE-2002-1865

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (2) Linksys Etherfast BEFW11S4 Wireless AP + Cable/DSL Router 1.37.2 up to and including 1.42.7 and Linksys WAP11 1.3 and 1.4, allows remote malicious users to cause a denial of service (crash) via a long header, as demonstrated using the Host header.

Vulnerable Product Search on Vulmon Subscribe to Product

d-link di-804 4.68

d-link dl-704 2.56_b5

linksys befw11s4 1.4.2.7

linksys befw11s4 1.40.3

linksys befw11s4 1.42.7

linksys wap11 1.3

linksys wap11 1.4

d-link dl-704 2.56_b6

linksys befw11s4 1.37.2b

linksys befw11s4 1.37.2

linksys befw11s4 1.37.9b

Exploits

source: wwwsecurityfocuscom/bid/6090/info A denial of service vulnerability has been reported for several networking devices The condition will be triggered when the embedded web server, used by the devices, receives an overly long HTTP header An attacker can exploit this vulnerability to cause the device to stop functioning Rebootin ...