CVE-2013-2600
- EPSS 0.49%
- Published 01.11.2019 12:15:10
- Last modified 21.11.2024 01:52:01
MiniUPnPd has information disclosure use of snprintf()
CVE-2019-12106
- EPSS 0.69%
- Published 15.05.2019 23:29:00
- Last modified 21.11.2024 04:22:12
The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability.
CVE-2019-12108
- EPSS 0.54%
- Published 15.05.2019 23:29:00
- Last modified 21.11.2024 04:22:13
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for int_port.
CVE-2019-12109
- EPSS 0.54%
- Published 15.05.2019 23:29:00
- Last modified 21.11.2024 04:22:13
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for rem_port.
CVE-2019-12111
- EPSS 1.03%
- Published 15.05.2019 23:29:00
- Last modified 21.11.2024 04:22:13
A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.
CVE-2017-1000494
- EPSS 0.17%
- Published 03.01.2018 14:29:00
- Last modified 21.11.2024 03:04:51
Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact
CVE-2017-8798
- EPSS 27.29%
- Published 11.05.2017 01:29:06
- Last modified 20.04.2025 01:37:25
Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2013-0229
- EPSS 77.99%
- Published 31.01.2013 21:55:01
- Last modified 11.04.2025 00:51:21
The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.
- EPSS 80.14%
- Published 31.01.2013 21:55:01
- Last modified 11.04.2025 00:51:21
Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.
CVE-2013-1461
- EPSS 0.69%
- Published 31.01.2013 21:55:01
- Last modified 11.04.2025 00:51:21
The ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and service crash) via a SOAPAction header that lacks a # (pound sig...