Showing 2 vulnerabilities on this page for uc-httpd

Signals CISA KEV Ransomware Nuclei
xiongmaitech vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

xiongmaitech uc-httpd Improper Restriction of Operations within the Bounds of a Memory Buffer

Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

CWE-119Jun 8, 20181 related artifact
CVSS9.8v3.0EPSS39.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

xiongmaitech uc-httpd Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.

CWE-22Apr 7, 2017
CVSS9.8v3.0EPSS29%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX