Miniupnp Project
Miniupnp Project Miniupnpd: vulnerabilidades y CVE
Miniupnp Project Miniupnpd tiene 12 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-5720 | Alta (7.1) | 1.1% | — | 17 abr 2026 | miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a… |
| CVE-2013-2600 | Alta (7.5) | 2.3% | — | 1 nov 2019 | MiniUPnPd has information disclosure use of snprintf() |
| CVE-2019-12111 | Alta (7.5) | 3.4% | — | 15 may 2019 | A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c. |
| CVE-2019-12109 | Alta (7.5) | 2.8% | — | 15 may 2019 | A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for rem_port. |
| CVE-2019-12108 | Alta (7.5) | 2.8% | — | 15 may 2019 | A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for int_port. |
| CVE-2019-12106 | Alta (7.5) | 2.8% | — | 15 may 2019 | The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability. |
| CVE-2017-1000494 | Alta (7.8) | 0.47% | — | 3 ene 2018 | Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have… |
| CVE-2017-8798 | Crítica (9.8) | 24% | — | 11 may 2017 | Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact. |
| CVE-2013-1462 | Alta (7.8) | 1.8% | — | 31 ene 2013 | Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (incorrect memory copy) via a… |
| CVE-2013-1461 | Alta (7.8) | 2.8% | — | 31 ene 2013 | The ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and service crash) via a SOAPAction… |
| CVE-2013-0230 | Alta (10) | 69% | — | 31 ene 2013 | Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method. |
| CVE-2013-0229 | Alta (7.8) | 76% | — | 31 ene 2013 | The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.