MiniShare
by Minishare
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-19862 | Cri | 0.68 | 9.8 | 0.13 | Jan 3, 2019 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is discontinued. | ||
| CVE-2018-19861 | Cri | 0.68 | 9.8 | 0.13 | Jan 3, 2019 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued. | ||
| CVE-2019-17601 | Cri | 0.64 | 9.8 | 0.03 | Oct 15, 2019 | In MiniShare 1.4.1, there is a stack-based buffer overflow via an HTTP CONNECT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19862 and CVE-2018-19861. NOTE: this product is discontinued. | ||
| CVE-2004-2271 | 0.09 | — | 0.72 | Dec 31, 2004 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | |||
| CVE-2004-2035 | 0.03 | — | 0.04 | May 26, 2004 | MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences. | |||
| CVE-2007-2315 | 0.00 | — | 0.02 | Apr 26, 2007 | MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections. |
- risk 0.68cvss 9.8epss 0.13
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is discontinued.
- risk 0.68cvss 9.8epss 0.13
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued.
- risk 0.64cvss 9.8epss 0.03
In MiniShare 1.4.1, there is a stack-based buffer overflow via an HTTP CONNECT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19862 and CVE-2018-19861. NOTE: this product is discontinued.
- CVE-2004-2271Dec 31, 2004risk 0.09cvss —epss 0.72
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2004-2035May 26, 2004risk 0.03cvss —epss 0.04
MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.
- CVE-2007-2315Apr 26, 2007risk 0.00cvss —epss 0.02
MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections.