← Back

Unix4lyfe

unix4lyfe

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Darkhttpd
darkhttpd

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Unix4lyfe
1Darkhttpd
Jun 17, 2026
Jan 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.
1Unix4lyfe
1Darkhttpd
Jun 17, 2026
Jan 22, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.
1Unix4lyfe
1Darkhttpd
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availab...Show more
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.Show less