Filtered by vendor Ritlabs Subscriptions
Filtered by product Tinyweb Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-5193 1 Ritlabs 1 Tinyweb 2025-06-23 5.3 Medium
A vulnerability was found in Ritlabs TinyWeb Server 1.94. It has been classified as problematic. Affected is an unknown function of the component Request Handler. The manipulation with the input %0D%0A leads to crlf injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-265830 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-34199 1 Ritlabs 1 Tinyweb 2025-06-13 8.6 High
TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.