Unix4lyfe
Unix4lyfe Darkhttpd: vulnerabilidades y CVE
Unix4lyfe Darkhttpd tiene 3 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE3
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-23771 | Crítica (9.8) | 1.1% | — | 22 ene 2024 | darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel. |
| CVE-2024-23770 | Media (5.5) | 0.24% | — | 22 ene 2024 | darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments. |
| CVE-2020-25691 | Alta (7.5) | 1.3% | — | 1 abr 2022 | A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system… |