allegrosoft RomPager 4.07

CPE Details

allegrosoft RomPager 4.07
4.07
2014-01-17
14h44 +00:00
2014-01-17
15h07 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:allegrosoft:rompager:4.07:*:*:*:*:*:*:*

Informations

Vendor

allegrosoft

Product

rompager

Version

4.07

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2014-9222 2014-12-24 17h00 +00:00 AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.
10
CVE-2014-9223 2014-12-24 17h00 +00:00 Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and products, allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors related to authorization.
10
CVE-2013-6786 2014-01-16 18h00 +00:00 Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a "URL redirection" issue that some sources list separately.
4.3