Unix4lyfe

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-23770

    darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.

    Last Modified: May 30, 2025
    Published: Jan 22, 2024

    CVE-2024-23771

    darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.

    Last Modified: May 30, 2025
    Published: Jan 22, 2024

    CVE-2020-25691

    A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.

    Last Modified: Nov 21, 2024
    Published: Apr 01, 2022
    Items Per Page