MiniUPnP Project MiniUPnPd 1.0 Release Candidate 8

CPE Details

MiniUPnP Project MiniUPnPd 1.0 Release Candidate 8
1.0
2019-06-26
14h39 +00:00
2019-06-26
14h39 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:miniupnp_project:miniupnpd:1.0:rc8:*:*:*:*:*:*

Informations

Vendor

miniupnp_project

Product

miniupnpd

Version

1.0

Update

rc8

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2019-12111 2019-05-15 20h23 +00:00 A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in copyIPv6IfDifferent in pcpserver.c.
7.5
High
CVE-2019-12109 2019-05-15 20h23 +00:00 A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for rem_port.
7.5
High
CVE-2019-12108 2019-05-15 20h23 +00:00 A Denial Of Service vulnerability in MiniUPnP MiniUPnPd through 2.1 exists due to a NULL pointer dereference in GetOutboundPinholeTimeout in upnpsoap.c for int_port.
7.5
High
CVE-2017-1000494 2018-01-03 13h00 +00:00 Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact
7.8
High
CVE-2013-0229 2013-01-31 20h00 +00:00 The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.
7.8
CVE-2013-0230 2013-01-31 20h00 +00:00 Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.
10
CVE-2013-1461 2013-01-31 20h00 +00:00 The ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and service crash) via a SOAPAction header that lacks a # (pound sign) character, a different vulnerability than CVE-2013-0230.
7.8
CVE-2013-1462 2013-01-31 20h00 +00:00 Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (incorrect memory copy) via a SOAPAction header that lacks a " (double quote) character, a different vulnerability than CVE-2013-0230.
7.8