VYPR
Vendor

darkhttpd

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2020-25691HigApr 1, 2022
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.

  • CVE-2024-23771CriJan 22, 2024
    risk 0.00cvss 9.8epss 0.01

    darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.

  • CVE-2024-23770MedJan 22, 2024
    risk 0.00cvss 5.5epss 0.00

    darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.