Readymedia Project Readymedia vulnerabilities

5 known vulnerabilities affecting readymedia_project/readymedia.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH2

Vulnerabilities

Page 1 of 1
CVE-2023-47430HIGHCVSS 7.5v1.3.32024-03-25
CVE-2023-47430 [HIGH] CWE-787 CVE-2023-47430: Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a deni Stack-buffer-overflow vulnerability in ReadyMedia (MiniDLNA) v1.3.3 allows attackers to cause a denial of service via via the SendContainer() function at tivo_commands.c.
nvd
CVE-2023-33476CRITICALCVSS 9.8≥ 1.1.15, ≤ 1.3.22023-06-02
CVE-2023-33476 [CRITICAL] CWE-787 CVE-2023-33476: ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnera ReadyMedia (MiniDLNA) versions from 1.1.15 up to 1.3.2 is vulnerable to Buffer Overflow. The vulnerability is caused by incorrect validation logic when handling HTTP requests using chunked transport encoding. This results in other code later using attacker-controlled chunk values that exceed the length of the allocated buffer, resulting in out-of-
nvd
CVE-2022-26505HIGHCVSS 7.4fixed in 1.3.12022-03-06
CVE-2022-26505 [HIGH] CWE-290 CVE-2022-26505: A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to e A DNS rebinding issue in ReadyMedia (formerly MiniDLNA) before 1.3.1 allows a remote web server to exfiltrate media files.
nvd
CVE-2020-28926CRITICALCVSS 9.8fixed in 1.3.02020-11-30
CVE-2020-28926 [CRITICAL] CWE-120 CVE-2020-28926: ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UP ReadyMedia (aka MiniDLNA) before versions 1.3.0 allows remote code execution. Sending a malicious UPnP HTTP request to the miniDLNA service using HTTP chunked encoding can lead to a signedness bug resulting in a buffer overflow in calls to memcpy/memmove.
nvd
CVE-2013-2738CRITICALCVSS 9.8fixed in 1.1.02019-11-01
CVE-2013-2738 [CRITICAL] CWE-89 CVE-2013-2738: minidlna has SQL Injection that may allow retrieval of arbitrary files minidlna has SQL Injection that may allow retrieval of arbitrary files
nvd