Miniupnp Project

Miniupnpd

13 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 07.10.2026 11:59:39
  • Zuletzt bearbeitet 07.10.2026 18:17:17

MiniUPnPd through 2.3.11 built with --strict contains a divide-by-zero vulnerability in ProcessSSDPData() that allows unauthenticated local network attackers to crash the daemon. Attackers can send a single multicast M-SEARCH datagram with MX: 0 and ...

  • EPSS 0.67%
  • Veröffentlicht 17.04.2026 21:39:54
  • Zuletzt bearbeitet 29.06.2026 14:22:29

miniupnpd contains an integer underflow vulnerability in SOAPAction header parsing that allows remote attackers to cause a denial of service or information disclosure by sending a malformed SOAPAction header with a single quote. Attackers can trigger...

Exploit
  • EPSS 2.34%
  • Veröffentlicht 01.11.2019 12:15:10
  • Zuletzt bearbeitet 21.11.2024 01:52:01

MiniUPnPd has information disclosure use of snprintf()

Exploit
  • EPSS 2.83%
  • Veröffentlicht 15.05.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:12

The updateDevice function in minissdpd.c in MiniUPnP MiniSSDPd 1.4 and 1.5 allows a remote attacker to crash the process due to a Use After Free vulnerability.

Exploit
  • EPSS 2.75%
  • Veröffentlicht 15.05.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:13

A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for int_port.

Exploit
  • EPSS 2.75%
  • Veröffentlicht 15.05.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:13

A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for rem_port.

Exploit
  • EPSS 3.4%
  • Veröffentlicht 15.05.2019 23:29:00
  • Zuletzt bearbeitet 21.11.2024 04:22:13

A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.

Exploit
  • EPSS 0.47%
  • Veröffentlicht 03.01.2018 14:29:00
  • Zuletzt bearbeitet 21.11.2024 03:04:51

Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact

Exploit
  • EPSS 24.03%
  • Veröffentlicht 11.05.2017 01:29:06
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.

  • EPSS 76.4%
  • Veröffentlicht 31.01.2013 21:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.