Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown

CVE-2023-47793

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in acmethemes Acme Fix Images allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Acme Fix Images: from n/a through 1.0.0.
0
Attacker Value
Unknown

CVE-2024-0263

Disclosure Date: January 07, 2024 (last updated January 11, 2024)
A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-249819.
Attacker Value
Unknown

CVE-2023-38198

Disclosure Date: July 13, 2023 (last updated October 08, 2023)
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
Attacker Value
Unknown

CVE-2007-0158

Disclosure Date: December 27, 2019 (last updated November 27, 2024)
thttpd 2007 has buffer underflow.
Attacker Value
Unknown

CVE-2012-5640

Disclosure Date: November 25, 2019 (last updated November 27, 2024)
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files
Attacker Value
Unknown

CVE-2018-18778

Disclosure Date: October 29, 2018 (last updated November 27, 2024)
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
0
Attacker Value
Unknown

CVE-2017-17663

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution.
0
Attacker Value
Unknown

CVE-2015-1548

Disclosure Date: February 10, 2015 (last updated October 05, 2023)
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read.
0
Attacker Value
Unknown

CVE-2014-4927

Disclosure Date: July 24, 2014 (last updated October 05, 2023)
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request.
0
Attacker Value
Unknown

CVE-2013-0348

Disclosure Date: December 13, 2013 (last updated October 05, 2023)
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
0