tiny-http project records
2 published records for vendor tiny-http project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2017-16097No exploit | tiny-http is a simple http server.tiny-http project · tiny-http · CWE-22 | High7.5 | — | 2.0% | Jun 6, 2018 |
26Monitor | CVE-2020-35884No exploit | An issue was discovered in the tiny_http crate through 2020-06-16 for Rust.tiny-http project · tiny-http · CWE-444 | Medium6.5 | — | 1.1% | Dec 31, 2020 |
- CVE-2017-1609731Monitor
tiny-http is a simple http server.
HighCVSS 7.5No exploitEPSS 2%tiny-http project · tiny-httpJun 6, 2018
- CVE-2020-3588426Monitor
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust.
MediumCVSS 6.5No exploitEPSS 1%tiny-http project · tiny-httpDec 31, 2020