CVE-2018-18778
https://notcve.org/view.php?id=CVE-2018-18778
ACME mini_httpd before 1.30 lets remote users read arbitrary files. ACME mini_httpd en versiones anteriores a la 1.30 permite que usuarios remotos lean archivos arbitrarios. • https://github.com/auk0x01/CVE-2018-18778-Scanner https://github.com/cyberharsh/Mini_httpd-CVE-2018-18778 http://www.acme.com/software/mini_httpd • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2017-17663
https://notcve.org/view.php?id=CVE-2017-17663
The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution. La implementación htpasswd de mini_httpd, en versiones anteriores a la v1.28 y de thttpd, en versiones anteriores a la v2.28, se ha visto afectada por un desbordamiento de búfer que podría ser explotado de forma remota para ejecutar código. • http://acme.com/updates/archive/199.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-1548
https://notcve.org/view.php?id=CVE-2015-1548
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read. mini_httpd 1.21 y anteriores permite a atacantes remotos obtener información sensible de la memoria de procesos a través de una solicitud HTTP con una cadena de protocolo largo, lo que provoca un cálculo del tamaño de respuesta incorrecta y una lectura fuera de rango. • http://itinsight.hu/en/posts/articles/2015-01-23-mini-httpd http://www.securityfocus.com/bid/73450 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2014-4927 – ACME micro_httpd - Denial of Service
https://notcve.org/view.php?id=CVE-2014-4927
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (crash) via a long string in the URI in a GET request. Desbordamiento de buffer en ACME micro_httpd, utilizado en los routers D-Link DSL2750U y DSL2740U y NetGear WGR614 y MR-ADSL-DG834 permite a atacantes remotos causar una denegación de servicio (caída) a través de una cadena larga en la URI en una solicitud GET. ACME micro_httpd suffers from a buffer overflow vulnerability that can cause a denial of service. • https://www.exploit-db.com/exploits/34102 http://osvdb.org/show/osvdb/109356 http://packetstormsecurity.com/files/127544/ACME-micro_httpd-Denial-Of-Service.html http://www.exploit-db.com/exploits/34102 http://www.securityfocus.com/bid/68746 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2013-0348
https://notcve.org/view.php?id=CVE-2013-0348
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file. thttpd.c en sthttpd antes de 2.26.4-r2 y httpd 2.25b usa permisos de lectura universales para / var / log / thttpd.log, lo que permite a usuarios locales obtener información sensible mediante la lectura del archivo. • http://lists.opensuse.org/opensuse-updates/2013-12/msg00050.html http://lists.opensuse.org/opensuse-updates/2014-01/msg00015.html http://opensource.dyc.edu/gitweb/?p=sthttpd.git%3Ba=commitdiff%3Bh=d2e186dbd58d274a0dea9b59357edc8498b5388d http://www.openwall.com/lists/oss-security/2013/02/23/7 https://bugs.gentoo.org/show_bug.cgi?id=458896 https://bugzilla.redhat.com/show_bug.cgi?id=924857 • CWE-264: Permissions, Privileges, and Access Controls •