CRITICAL9.1CVE-2023-46586cgi.c in weborf .0.17, 0.18, 0.19, and 0.20 (before 1.0) lacks '\0' termination of the path for CGI scripts because strncpy is misused.
from 0, < 0.17-3+deb11u1
HIGH7.5CVE-2011-0529Weborf before 0.12.5 is affected by a Denial of Service (DOS) due to malformed fields in HTTP.
from 0, < 0.12.5-1
—CVE-2010-3306Directory traversal vulnerability in the modURL function in instance.c in Weborf before 0.12.3 allows remote attackers to read arbitrary fi…
from 0, < 0.12.3-1
—Weborf HTTP Server 0.12.1 and earlier allows remote attackers to cause a denial of service (crash) via Unicode characters in a Connection H…
from 0, < 0.12.2-1
—Galileo Students Team Weborf before 0.12.1 allows remote attackers to cause a denial of service (crash) via a crafted Range header.