CVE-2012-1035

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
08/02/2012
Last modified:
11/04/2025

Description

AdaCore Ada Web Services (AWS) before 2.10.2 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adacore:ada_web_services:*:*:*:*:*:*:*:* 2.10.1 (including)
cpe:2.3:a:adacore:ada_web_services:2.10.0:*:*:*:*:*:*:*