Minishare is a lightweight HTTP server with a minimal product footprint, used in scenarios where a simple file-sharing capability is needed without a full web server stack. The available disclosures reflect the constraints of this narrowly scoped utility and cluster around general weakness categories rather than a specific parseable pattern. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minishare over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2271HIGH Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | Dec 31, 2004 | 7.5 | 78 | NO | YES |
CVE-2018-19862CRITICAL Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is discontinued. | Jan 3, 2019 | 9.8 | 50 | NO | YES |
CVE-2018-19861CRITICAL Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued. | Jan 3, 2019 | 9.8 | 48 | NO | YES |
CVE-2019-17601CRITICAL In MiniShare 1.4.1, there is a stack-based buffer overflow via an HTTP CONNECT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19 | Oct 15, 2019 | 9.8 | 31 | NO | NO |
CVE-2020-13768CRITICAL In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018 | Jun 4, 2020 | 9.8 | 30 | NO | NO |
CVE-2004-2035MEDIUM MiniShare 1.3.2 allows remote attackers to cause a denial of service (crash) via a malformed HTTP GET or HEAD request without the proper number of trailing CRLF sequences. | May 26, 2004 | 5.0 | 25 | NO | YES |
CVE-2007-2315HIGH MiniShare 1.5.4, and possibly earlier, allows remote attackers to cause a denial of service (application crash) via a flood of requests for new connections. | Apr 26, 2007 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minishare.
Media articles that mention a CVE ID that affects a product developed by Minishare — matched by CVE ID, not by vendor name.