Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2013-2600

Disclosure Date: November 01, 2019 (last updated November 27, 2024)
MiniUPnPd has information disclosure use of snprintf()
Attacker Value
Unknown

CVE-2019-12110

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
An AddPortMapping Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in upnpredirect.c.
0
Attacker Value
Unknown

CVE-2019-12106

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability.
0
Attacker Value
Unknown

CVE-2019-12111

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.
Attacker Value
Unknown

CVE-2019-12107

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
The upnp_event_prepare function in upnpevents.c in MiniUPnP MiniUPnPd through 2.1 allows a remote attacker to leak information from the heap due to improper validation of an snprintf return value.
0
Attacker Value
Unknown

CVE-2019-12108

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for int_port.
0
Attacker Value
Unknown

CVE-2019-12109

Disclosure Date: May 15, 2019 (last updated November 27, 2024)
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for rem_port.
0
Attacker Value
Unknown

CVE-2017-1000494

Disclosure Date: January 03, 2018 (last updated November 26, 2024)
Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact
0
Attacker Value
Unknown

CVE-2017-8798

Disclosure Date: May 11, 2017 (last updated November 26, 2024)
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
0
Attacker Value
Unknown

CVE-2013-0229

Disclosure Date: January 31, 2013 (last updated October 05, 2023)
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.
0