Show filters
32 Total Results
Displaying 21-30 of 32
Sort by:
Attacker Value
Unknown
CVE-2018-10717
Disclosure Date: May 03, 2018 (last updated November 26, 2024)
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file, a different vulnerability than CVE-2018-10677.
0
Attacker Value
Unknown
CVE-2018-10677
Disclosure Date: May 02, 2018 (last updated November 26, 2024)
The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file.
0
Attacker Value
Unknown
CVE-2017-1000494
Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact
0
Attacker Value
Unknown
CVE-2017-8798
Disclosure Date: May 11, 2017 (last updated November 26, 2024)
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
0
Attacker Value
Unknown
CVE-2016-3179
Disclosure Date: March 24, 2017 (last updated November 26, 2024)
The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (invalid free and daemon crash) via vectors related to error handling.
0
Attacker Value
Unknown
CVE-2016-3178
Disclosure Date: March 24, 2017 (last updated November 26, 2024)
The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (out-of-bounds memory access and daemon crash) via vectors involving a negative length value.
0
Attacker Value
Unknown
CVE-2015-6031
Disclosure Date: November 02, 2015 (last updated October 05, 2023)
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name.
0
Attacker Value
Unknown
CVE-2014-3985
Disclosure Date: September 11, 2014 (last updated October 05, 2023)
The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) via crafted headers that trigger an out-of-bounds read.
0
Attacker Value
Unknown
CVE-2013-0229
Disclosure Date: January 31, 2013 (last updated October 05, 2023)
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.
0
Attacker Value
Unknown
CVE-2013-0230
Disclosure Date: January 31, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.
0