unix4lyfe darkhttpd CVE Vulnerabilities (3)

CVEs: 3 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting unix4lyfe darkhttpd (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-23771 darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel. [email protected] 9.8 0.21% 2024-01-22 2025-05-30
CVE-2024-23770 darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments. [email protected] 5.5 0.03% 2024-01-22 2025-05-30
CVE-2020-25691 A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability. [email protected] 7.5 0.47% 2022-04-01 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence