MiniShare
by Minishare
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2004-2271 | 0.10 | — | 0.82 | Dec 31, 2004 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | |||
| CVE-2018-19862 | 0.05 | — | 0.28 | Jan 3, 2019 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is discontinued. | |||
| CVE-2018-19861 | 0.05 | — | 0.28 | Jan 3, 2019 | Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued. | |||
| CVE-2004-2035 | 0.04 | — | 0.09 | May 26, 2004 | MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences. | |||
| CVE-2020-13768 | 0.00 | — | 0.01 | Jun 4, 2020 | In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19861, CVE-2018-19862, and CVE-2019-17601. NOTE: this product is discontinued. | |||
| CVE-2007-2315 | 0.00 | — | 0.01 | Apr 26, 2007 | MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections. |
- CVE-2004-2271Dec 31, 2004risk 0.10cvss —epss 0.82
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
- CVE-2018-19862Jan 3, 2019risk 0.05cvss —epss 0.28
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is discontinued.
- CVE-2018-19861Jan 3, 2019risk 0.05cvss —epss 0.28
Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued.
- CVE-2004-2035May 26, 2004risk 0.04cvss —epss 0.09
MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences.
- CVE-2020-13768Jun 4, 2020risk 0.00cvss —epss 0.01
In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19861, CVE-2018-19862, and CVE-2019-17601. NOTE: this product is discontinued.
- CVE-2007-2315Apr 26, 2007risk 0.00cvss —epss 0.01
MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections.