Lucene search

K

Civetweb Security Vulnerabilities

cve
cve

CVE-2018-12684

Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI...

7.1CVSS

6.5AI Score

0.001EPSS

2022-10-03 04:22 PM
23
cve
cve

CVE-2020-27304

The CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file upload mechanism, via the mg_handle_form_request API. Web applications that use the file upload form handler, and use parts of the user-controlled...

9.8CVSS

9.3AI Score

0.003EPSS

2021-10-21 04:15 PM
88
cve
cve

CVE-2019-3821

A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust file descriptors for ceph-radosgw service resulting in a remote denial of...

7.5CVSS

7.3AI Score

0.009EPSS

2019-03-27 01:29 PM
58