Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown
CVE-2024-23771
Disclosure Date: January 22, 2024 (last updated January 27, 2024)
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.
0
Attacker Value
Unknown
CVE-2024-23770
Disclosure Date: January 22, 2024 (last updated January 27, 2024)
darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.
0
Attacker Value
Unknown
CVE-2020-25691
Disclosure Date: April 01, 2022 (last updated February 01, 2024)
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.
0