Show filters
871 Total Results
Displaying 81-90 of 871
Sort by:
Attacker Value
Unknown
CVE-2023-50694
Disclosure Date: January 19, 2024 (last updated March 06, 2024)
An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to send a malicious crafted request due to insufficient parsing in the parser.nim component.
0
Attacker Value
Unknown
CVE-2021-4433
Disclosure Date: January 18, 2024 (last updated January 25, 2024)
A vulnerability was found in Karjasoft Sami HTTP Server 2.0. It has been classified as problematic. Affected is an unknown function of the component HTTP HEAD Rrequest Handler. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250836.
0
Attacker Value
Unknown
CVE-2024-0419
Disclosure Date: January 11, 2024 (last updated January 19, 2024)
A vulnerability was found in Jasper httpdx up to 1.5.4 and classified as problematic. This issue affects some unknown processing of the component HTTP POST Request Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250439.
0
Attacker Value
Unknown
CVE-2024-0263
Disclosure Date: January 07, 2024 (last updated January 11, 2024)
A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-249819.
0
Attacker Value
Unknown
CVE-2024-22087
Disclosure Date: January 05, 2024 (last updated January 12, 2024)
route in main.c in Pico HTTP Server in C through f3b69a6 has an sprintf stack-based buffer overflow via a long URI, leading to remote code execution.
0
Attacker Value
Unknown
CVE-2024-22049
Disclosure Date: January 04, 2024 (last updated February 14, 2025)
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.
0
Attacker Value
Unknown
CVE-2023-52267
Disclosure Date: December 31, 2023 (last updated January 10, 2024)
ehttp 1.0.6 before 17405b9 has a simple_log.cpp _log out-of-bounds-read during error logging for long strings.
0
Attacker Value
Unknown
CVE-2023-52266
Disclosure Date: December 31, 2023 (last updated January 10, 2024)
ehttp 1.0.6 before 17405b9 has an epoll_socket.cpp read_func use-after-free. An attacker can make many connections over a short time to trigger this.
0
Attacker Value
Unknown
CVE-2023-46918
Disclosure Date: December 27, 2023 (last updated January 06, 2024)
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.
0
Attacker Value
Unknown
CVE-2023-46919
Disclosure Date: December 27, 2023 (last updated October 01, 2024)
Phlox com.phlox.simpleserver (aka Simple HTTP Server) 1.8 and com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus have a hardcoded aKySWb2jjrr4dzkYXczKRt7K (AES) encryption key. An attacker with physical access to the application's source code or binary can extract this key & use it decrypt the TLS secret.
0