CVE-2019-19943

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
28/02/2020
Last modified:
21/07/2021

Description

The HTTP service in quickweb.exe in Pablo Quick 'n Easy Web Server 3.3.8 allows Remote Unauthenticated Heap Memory Corruption via a large host or domain parameter. It may be possible to achieve remote code execution because of a double free.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pablosoftwaresolutions:quick_\'n_easy_web_server:*:*:*:*:*:*:*:* 3.3.8 (including)


References to Advisories, Solutions, and Tools