5
CVSSv2

CVE-2004-2129

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

SurfNOW 2.2 allows remote malicious users to cause a denial of service (crash) via a series of long HTTP GET requests, possibly triggering a buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

loom software surfnow professional 1.6

loom software surfnow professional 2.0

loom software surfnow standard 2.0

loom software surfnow standard 2.1

loom software surfnow professional 1.2

loom software surfnow standard 1.2

loom software surfnow standard 1.4

loom software surfnow professional 2.1

loom software surfnow professional 2.2

loom software surfnow standard 2.2

loom software surfnow professional 1.4

loom software surfnow professional 1.5

loom software surfnow standard 1.5

loom software surfnow standard 1.6

Exploits

source: wwwsecurityfocuscom/bid/9519/info A problem has been identified in the handling of specific types of requests by SurfNOW Upon receiving specially crafted HTTP GET requests, it is possible for a remote attacker to crash a vulnerable implementation, denying service to the user GET \aaaaaaaaaaaaa[ 490 kb of a ]aaaa HTTP/11\n\n\n ...