Filtered by vendor Miniupnp Project
Subscribe
Total
32 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2019-20219 | 1 Miniupnp Project | 1 Ngiflib | 2020-01-08 | 6.8 MEDIUM | 8.8 HIGH |
ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor in ngiflib.c. | |||||
CVE-2013-2600 | 2 Debian, Miniupnp Project | 2 Debian Linux, Miniupnpd | 2019-11-04 | 5.0 MEDIUM | 7.5 HIGH |
MiniUPnPd has information disclosure use of snprintf() | |||||
CVE-2018-11657 | 1 Miniupnp Project | 1 Ngiflib | 2019-10-03 | 5.0 MEDIUM | 7.5 HIGH |
ngiflib.c in MiniUPnP ngiflib 0.4 has an infinite loop in DecodeGifImg and LoadGif. | |||||
CVE-2015-6031 | 4 Canonical, Debian, Miniupnp Project and 1 more | 5 Ubuntu Linux, Debian Linux, Miniupnpc and 2 more | 2019-06-18 | 6.8 MEDIUM | N/A |
Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name. | |||||
CVE-2017-1000494 | 1 Miniupnp Project | 1 Miniupnpd | 2019-05-30 | 4.6 MEDIUM | 7.8 HIGH |
Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact | |||||
CVE-2019-12106 | 1 Miniupnp Project | 1 Miniupnpd | 2019-05-27 | 5.0 MEDIUM | 7.5 HIGH |
The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability. | |||||
CVE-2018-11578 | 1 Miniupnp Project | 1 Ngiflib | 2018-07-13 | 4.3 MEDIUM | 6.5 MEDIUM |
GifIndexToTrueColor in ngiflib.c in MiniUPnP ngiflib 0.4 has a Segmentation fault. | |||||
CVE-2018-11576 | 1 Miniupnp Project | 1 Ngiflib | 2018-06-28 | 7.5 HIGH | 9.8 CRITICAL |
ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor. | |||||
CVE-2013-0230 | 1 Miniupnp Project | 1 Miniupnpd | 2016-12-08 | 10.0 HIGH | N/A |
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method. | |||||
CVE-2013-1462 | 1 Miniupnp Project | 1 Miniupnpd | 2015-10-08 | 7.8 HIGH | N/A |
Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (incorrect memory copy) via a SOAPAction header that lacks a " (double quote) character, a different vulnerability than CVE-2013-0230. | |||||
CVE-2013-1461 | 1 Miniupnp Project | 1 Miniupnpd | 2015-10-08 | 7.8 HIGH | N/A |
The ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and service crash) via a SOAPAction header that lacks a # (pound sign) character, a different vulnerability than CVE-2013-0230. | |||||
CVE-2013-0229 | 1 Miniupnp Project | 1 Miniupnpd | 2015-10-08 | 7.8 HIGH | N/A |
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read. |