VYPR

Webobjects

by Apple Inc.

CVEs (4)

  • CVE-2022-37724MedSep 14, 2022
    risk 0.33cvss 6.1epss 0.01

    Project Wonder WebObjects 1.0 through 5.4.3 is vulnerable to Arbitrary HTTP Header injection and URL- or Header-based XSS reflection in all web-server adaptor interfaces.

  • CVE-2000-0299Apr 4, 2000
    risk 0.03cvss epss 0.05

    Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of service via an HTTP request with long headers such as Accept.

  • CVE-2011-3998Nov 9, 2011
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in Apple WebObjects 5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2008-2318Jul 14, 2008
    risk 0.00cvss epss 0.01

    The WOHyperlink implementation in WebObjects in Apple Xcode tools before 3.1 appends local session IDs to generated non-local URLs, which allows remote attackers to obtain potentially sensitive information by reading the requests for these URLs.