Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2024-23771

Disclosure Date: January 22, 2024 (last updated January 27, 2024)
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.
Attacker Value
Unknown

CVE-2024-23770

Disclosure Date: January 22, 2024 (last updated January 27, 2024)
darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.
Attacker Value
Unknown

CVE-2020-25691

Disclosure Date: April 01, 2022 (last updated February 01, 2024)
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.