Miniweb Http Server is a lightweight, embedded web server product exposed to a durable vulnerability pattern centered on path-traversal and buffer-boundary weaknesses that are characteristic of simplified HTTP implementations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Miniweb Http Server over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0337HIGH Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI. | Jan 17, 2008 | 7.5 | 30 | NO | YES |
CVE-2020-29596HIGH MiniWeb HTTP server 0.8.19 allows remote attackers to cause a denial of service (daemon crash) via a long name for the first parameter in a POST request. | Dec 21, 2020 | 7.5 | 24 | NO | NO |
CVE-2007-3159MEDIUM http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negative value in the Content-Length HTTP header. | Jun 11, 2007 | 5.0 | 24 | NO | YES |
CVE-2008-0338MEDIUM Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary dire | Jan 17, 2008 | 5.0 | 23 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Miniweb Http Server.
Media articles that mention a CVE ID that affects a product developed by Miniweb Http Server — matched by CVE ID, not by vendor name.