Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown
CVE-2023-47793
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in acmethemes Acme Fix Images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Acme Fix Images: from n/a through 1.0.0.
0
Attacker Value
Unknown
CVE-2024-0263
Disclosure Date: January 07, 2024 (last updated January 11, 2024)
A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-249819.
0
Attacker Value
Unknown
CVE-2023-38198
Disclosure Date: July 13, 2023 (last updated October 08, 2023)
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
0
Attacker Value
Unknown
CVE-2007-0158
Disclosure Date: December 27, 2019 (last updated November 27, 2024)
thttpd 2007 has buffer underflow.
0
Attacker Value
Unknown
CVE-2012-5640
Disclosure Date: November 25, 2019 (last updated November 27, 2024)
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files
0
Attacker Value
Unknown
CVE-2018-18778
Disclosure Date: October 29, 2018 (last updated November 27, 2024)
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
0
Attacker Value
Unknown
CVE-2017-17663
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution.
0
Attacker Value
Unknown
CVE-2015-1548
Disclosure Date: February 10, 2015 (last updated October 05, 2023)
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read.
0
Attacker Value
Unknown
CVE-2014-4927
Disclosure Date: July 24, 2014 (last updated October 05, 2023)
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.
0
Attacker Value
Unknown
CVE-2013-0348
Disclosure Date: December 13, 2013 (last updated October 05, 2023)
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
0