CVE-2025-62689
- EPSS 0.05%
- Veröffentlicht 10.11.2025 04:10:57
- Zuletzt bearbeitet 14.11.2025 18:05:06
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an...
CVE-2025-59777
- EPSS 0.05%
- Veröffentlicht 10.11.2025 04:10:44
- Zuletzt bearbeitet 14.11.2025 18:07:33
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an...
CVE-2023-27371
- EPSS 0.08%
- Veröffentlicht 28.02.2023 20:15:10
- Zuletzt bearbeitet 21.11.2024 07:52:46
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST ...
- EPSS 0.42%
- Veröffentlicht 25.03.2021 19:15:15
- Zuletzt bearbeitet 21.11.2024 06:21:36
A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this v...
CVE-2013-7038
- EPSS 0.95%
- Veröffentlicht 13.12.2013 18:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain sensitive information or cause a denial of service (crash) via unspecified vectors that trigger an out-of-bounds read.
CVE-2013-7039
- EPSS 2.39%
- Veröffentlicht 13.12.2013 18:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitr...