Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2021-26843

Disclosure Date: February 07, 2021 (last updated February 22, 2025)
An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this is similar to CVE-2017-10671, but occurs in a different part of the de_dotdot function.
Attacker Value
Unknown

CVE-2017-10671

Disclosure Date: June 29, 2017 (last updated July 20, 2024)
Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename.
Attacker Value
Unknown

CVE-1999-1456

Disclosure Date: December 31, 1999 (last updated February 22, 2025)
thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.
0
Attacker Value
Unknown

CVE-1999-1457

Disclosure Date: November 16, 1999 (last updated February 22, 2025)
Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.
0