bigantsoft CVE 脆弱性と CVE 一覧(17)

製品(CPE): — CVE 件数: 17

bigantsoft 脆弱性概要

bigantsoft 関連製品全体の CVE とセキュリティ脆弱性情報を集約し、CVSS、EPSS、公開日、脆弱性情報データを掲載しています。

公開された問題は vendor risk sql injection、vendor risk cross-site scripting, and vendor risk csrf に関連することが多く、vendor surface software deployment and vendor surface production workloads の文脈で vendor impact data exposure and ファイル上書き などの暴露リスクを伴う場合があります。

掲載データは公開脆弱性情報とセキュリティ公告に基づき、過去の暴露面と修補優先度の評価に利用できます。

脆弱性分布の推移(直近24か月)

表示中 117 / 17 CVE 件数
«« 先頭 « 前へ 1 / 1 次へ »
CVE 概要 ソース CVSS 最大値 EPSS(%) 公開 更新
CVE-2025-0364 BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker can create an administrative user through the default exposed SaaS registration mechanism. Once an administrator, the attacker can upload and execute arbitrary PHP code using the "Cloud Storage Addin," leading to unauthenticated code execution. [email protected] 9.8 22.33% 2025-02-04 2025-09-29
CVE-2024-54761 BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter. [email protected] 6.3 0.82% 2025-01-09 2025-09-29
CVE-2021-43430 An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files. [email protected] 8.8 0.40% 2022-04-07 2024-11-21
CVE-2022-26281 BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue. [email protected] 7.5 0.18% 2022-04-05 2024-11-21
CVE-2022-23352 An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS). [email protected] 7.5 0.98% 2022-03-21 2024-11-21
CVE-2022-23350 BigAnt Software BigAnt Server v5.6.06 was discovered to contain a cross-site scripting (XSS) vulnerability. [email protected] 5.4 0.45% 2022-03-21 2024-11-21
CVE-2022-23349 BigAnt Software BigAnt Server v5.6.06 was discovered to contain a Cross-Site Request Forgery (CSRF). [email protected] 8.8 0.33% 2022-03-21 2024-11-21
CVE-2022-23348 BigAnt Software BigAnt Server v5.6.06 was discovered to utilize weak password hashes. [email protected] 5.3 1.21% 2022-03-21 2024-11-21
CVE-2022-23347 BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks. [email protected] 7.5 72.33% 2022-03-21 2024-11-21
CVE-2022-23346 BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues. [email protected] 8.8 0.74% 2022-03-21 2024-11-21
CVE-2022-23345 BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control. [email protected] 7.5 0.73% 2022-03-21 2024-11-21
CVE-2012-6275 Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH request or (2) the userid component in a DUPF request. [email protected] 10.0 76.51% 2013-02-24 2026-04-29
CVE-2012-6274 BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via unspecified vectors. [email protected] 5.0 75.34% 2013-02-24 2026-04-29
CVE-2012-6273 SQL injection vulnerability in BigAntSoft BigAnt IM Message Server allows remote attackers to execute arbitrary SQL commands via an SHU (aka search user) request. [email protected] 7.5 0.37% 2013-02-24 2026-04-29
CVE-2009-4661 Multiple buffer overflows in BigAnt Server 2.50 SP6 and earlier allow user-assisted remote attackers to cause a denial of service (application crash) via a crafted ZIP file that is not properly handled when the victim uses the (1) Update or (2) Plug-In console menu item. [email protected] 4.3 11.34% 2010-03-03 2026-04-29
CVE-2009-4660 Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to execute arbitrary code via a long GET request to TCP port 6660. [email protected] 10.0 80.67% 2010-03-03 2026-04-29
CVE-2008-1914 Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows remote attackers to execute arbitrary code via a long URI in a request to TCP port 6080. NOTE: some of these details are obtained from third party information. [email protected] 10.0 87.01% 2008-04-22 2026-04-23
«« 先頭 « 前へ 1 / 1 次へ »
cvelogic Threat Intelligence