T. Hauck maintains Jana Web Server, a niche web application platform where disclosed vulnerabilities tend to acquire public exploit code. The recurring weakness classifications in available disclosures are noted as placeholder entries in the NVD taxonomy, limiting the structural insight that typical classification allows. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by T. Hauck over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0557MEDIUM T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e). | Aug 14, 2001 | 5.0 | 32 | NO | YES |
CVE-2001-0558MEDIUM T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0 | Aug 14, 2001 | 5.0 | 30 | NO | YES |
CVE-1999-1082MEDIUM Directory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) attack. | Oct 8, 1999 | 5.0 | 25 | NO | YES |
CVE-1999-1083MEDIUM Directory traversal vulnerability in Jana proxy web server 1.45 allows remote attackers to ready arbitrary files via a .. (dot dot) attack. | Oct 8, 1999 | 5.0 | 23 | NO | YES |
CVE-2002-1061HIGH Multiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service and possibly execute arbitrary c | Oct 4, 2002 | 7.5 | 21 | NO | NO |
CVE-2002-1062HIGH Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) | Oct 4, 2002 | 7.5 | 20 | NO | NO |
CVE-2002-1066HIGH Thomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large message index value in a (1) RETR or | Oct 4, 2002 | 7.5 | 20 | NO | NO |
CVE-2002-1064MEDIUM Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote attackers to identify valid us | Oct 4, 2002 | 5.0 | 19 | NO | NO |
CVE-2002-1065HIGH Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier for remote attackers to gain p | Oct 4, 2002 | 7.5 | 19 | NO | NO |
CVE-2002-1063MEDIUM Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a large number of FTP PASV request | Oct 4, 2002 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by T. Hauck.
Media articles that mention a CVE ID that affects a product developed by T. Hauck — matched by CVE ID, not by vendor name.