Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2024-0263

Disclosure Date: January 07, 2024 (last updated January 11, 2024)
A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-249819.
Attacker Value
Unknown

CVE-2018-18778

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
0
Attacker Value
Unknown

CVE-2017-17663

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution.
0
Attacker Value
Unknown

CVE-2015-1548

Disclosure Date: February 10, 2015 (last updated October 05, 2023)
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2013-5019

Disclosure Date: July 31, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP request.
0
Attacker Value
Unknown

CVE-2009-4490

Disclosure Date: January 13, 2010 (last updated October 04, 2023)
mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
0
Attacker Value
Unknown

CVE-2001-0893

Disclosure Date: November 13, 2001 (last updated February 22, 2025)
Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
0