Vulnerability Details CVE-2020-25691
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-25691
-
cpe:2.3:a:unix4lyfe:darkhttpd:-
-
cpe:2.3:a:unix4lyfe:darkhttpd:1.13
-
cpe:2.3:a:unix4lyfe:darkhttpd:1.13-1