This page lists publicly disclosed CVE vulnerabilities affecting an an-http (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2003-1271 | Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTML as other users via a URL containing the script. | [email protected] | 4.3 | 0.58% | 2003-12-31 | 2026-04-16 |
| CVE-2003-1270 | AN HTTP 1.41e allows remote attackers to cause a denial of service (borken pipe) via an HTTP request to aux.cgi with a long argument, possibly triggering a buffer overflow or MS-DOS device vulnerability. | [email protected] | 5.0 | 2.37% | 2003-12-31 | 2026-04-16 |
| CVE-2003-1269 | AN HTTP 1.41e allows remote attackers to obtain the root web server path via an HTTP request with a long argument to a script, which leaks the path in an error message. | [email protected] | 5.0 | 0.35% | 2003-12-31 | 2026-04-16 |