Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown

CVE-2018-10717

Disclosure Date: May 03, 2018 (last updated November 26, 2024)
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file, a different vulnerability than CVE-2018-10677.
0
Attacker Value
Unknown

CVE-2018-10677

Disclosure Date: May 02, 2018 (last updated November 26, 2024)
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.
0
Attacker Value
Unknown

CVE-2017-1000494

Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact
0
Attacker Value
Unknown

CVE-2017-8798

Disclosure Date: May 11, 2017 (last updated November 26, 2024)
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2016-3179

Disclosure Date: March 24, 2017 (last updated November 26, 2024)
The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (invalid free and daemon crash) via vectors related to error handling.
Attacker Value
Unknown

CVE-2016-3178

Disclosure Date: March 24, 2017 (last updated November 26, 2024)
The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (out-of-bounds memory access and daemon crash) via vectors involving a negative length value.
Attacker Value
Unknown

CVE-2015-6031

Disclosure Date: November 02, 2015 (last updated October 05, 2023)
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.
0
Attacker Value
Unknown

CVE-2014-3985

Disclosure Date: September 11, 2014 (last updated October 05, 2023)
The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) via crafted headers that trigger an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2013-0229

Disclosure Date: January 31, 2013 (last updated October 05, 2023)
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.
0
Attacker Value
Unknown

CVE-2013-0230

Disclosure Date: January 31, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.
0