Direct Web Remoting
Getahead · 4 CVEs
CVE-2007-2377
MEDIUM
The Getahead Direct Web Remoting (DWR) framework 1.1.4 exchanges data using JavaScript Object Notation (JSON) without a…
Apr 30, 2007
CVE-2007-0185
HIGH
Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to cause a denial of service (memory exhaustion and se…
Jan 11, 2007
CVE-2007-0184
HIGH
Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a…
Jan 11, 2007
CVE-2006-6916
HIGH
Getahead Direct Web Remoting (DWR) before 1.1.3 allows attackers to cause a denial of service (infinite loop) via unkno…
Jan 11, 2007
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2007-2377 | The Getahead Direct Web Remoting (DWR) framework 1.1.4 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which al… | MEDIUM | 1.88% | Apr 30, 2007 |
| CVE-2007-0185 | Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to cause a denial of service (memory exhaustion and servlet outage) via unknown vectors relate… | HIGH | 1.51% | Jan 11, 2007 |
| CVE-2007-0184 | Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the includ… | HIGH | 1.49% | Jan 11, 2007 |
| CVE-2006-6916 | Getahead Direct Web Remoting (DWR) before 1.1.3 allows attackers to cause a denial of service (infinite loop) via unknown vectors related to "crafted input." | HIGH | 2.98% | Jan 11, 2007 |
Showing 1 to 4 of 4 CVEs