VYPR
Vendor

Allegrosoft

Products
6
CVEs
10
Across products
11
Status
Private

Products

6

Recent CVEs

10
  • CVE-2021-43978HigDec 8, 2021
    risk 0.46cvss 7.1epss 0.01

    Allegro WIndows 3.3.4152.0, embeds software administrator database credentials into its binary files, which allows users to access and modify data using the same credentials.

  • CVE-2021-42110HigDec 8, 2021
    risk 0.46cvss 7.1epss 0.00

    An issue was discovered in Allegro Windows (formerly Popsy Windows) before 3.3.4156.1. A standard user can escalate privileges to SYSTEM if the FTP module is installed, because of DLL hijacking.

  • CVE-2021-36489MedFeb 3, 2023
    risk 0.42cvss 6.5epss 0.01

    Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon.

  • CVE-2023-25392MedApr 10, 2023
    risk 0.31cvss 5.9epss 0.00

    Allegro Tech BigFlow <1.6 is vulnerable to Missing SSL Certificate Validation.

  • CVE-2024-0522MedJan 14, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Allegro RomPager 4.01. It has been classified as problematic. Affected is an unknown function of the file usertable.htm?action=delete of the component HTTP POST Request Handler. The manipulation of the argument username leads to cross-site request…

  • CVE-2014-9222Dec 24, 2014
    risk 0.08cvss epss 0.64

    AllegroSoft RomPager 4.34 and earlier, as used in Huawei Home Gateway products and other vendors and products, allows remote attackers to gain privileges via a crafted cookie that triggers memory corruption, aka the "Misfortune Cookie" vulnerability.

  • CVE-2000-0470Jun 1, 2000
    risk 0.04cvss epss 0.07

    Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request.

  • CVE-2026-16211LowJul 19, 2026
    risk 0.00cvss 2.6epss 0.00

    A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation Handler. Executing a manipulation of the…

  • CVE-2014-9223Dec 24, 2014
    risk 0.00cvss epss 0.06

    Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and products, allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors related to authorization.

  • CVE-2013-6786Jan 16, 2014
    risk 0.00cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote…