CVE-2015-1548
Essential information
- Published
- 10/02/2015 20:59
- Modified
- 07/05/2026 01:38
- Author
- AlienVault
- Creator
- AlienVault
- CVSS
- 5.0 (v2)
- CISA KEV
- No
- CWE
- CWE-119
- CVSS vector
-
AV:N/AC:L/Au:N/C:P/I:N/A:N— —
CVSS metrics
- Access vector
- Network
- Access complexity
- Low
- Authentication
- None
- Confidentiality impact
- Partial
- Integrity impact
- None
- Availability impact
- None
- Exploitability
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- —
- Attack complexity
- —
- Privileges required
- —
- User interaction
- —
- Scope
- —
- Confidentiality impact
- —
- Integrity impact
- —
- Availability impact
- —
- Exploit code maturity
- —
- Remediation level
- —
- Report confidence
- —
- Temporal score
- —
- Attack vector
- —
- Attack complexity
- —
- Attack requirements
- —
- Privileges required
- —
- User interaction
- —
- Confidentiality (V)
- —
- Confidentiality (S)
- —
- Integrity (V)
- —
- Integrity (S)
- —
- Availability (V)
- —
- Availability (S)
- —
- Exploit maturity
- —
Description
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protocol string, which triggers an incorrect response size calculation and an out-of-bounds read.
NVD status
- NVD
- View on NVD