← Vulnerability feed

Vulnerability record · CVE-2004-2271 · published 31 December 2004

CVE-2004-2271: MiniShare HTTP server buffer overflow via long GET request

MMinishare · Minimal Http Server

MiniShare 1.4.1 and earlier contains a buffer overflow that is triggered by a long HTTP GET request. A remote, unauthenticated attacker can send an oversized request to crash the server or execute arbitrary code in its context. The flaw is in an end-of-life minimal HTTP server, so exposure persists wherever the product is still deployed.

7.5 CVSS 2.0 High EPSS 72% · top 0.6%
7.5CVSS 2.0 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution with public exploit references and very high EPSS, though the product is old and likely limited in deployment.

What it is

MiniShare 1.4.1 and earlier contains a buffer overflow that is triggered by a long HTTP GET request. A remote, unauthenticated attacker can send an oversized request to crash the server or execute arbitrary code in its context. The flaw is in an end-of-life minimal HTTP server, so exposure persists wherever the product is still deployed.

Impact

An attacker gains remote code execution on the host running MiniShare, or at minimum can crash the service. Successful exploitation typically yields the privileges of the MiniShare process.

Attack surface

Reachable over the network through the HTTP listener; the CVSS vector AV:N/AC:L/Au:N confirms no authentication is required. No user interaction is needed because the attacker sends the malicious GET request directly to the server.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.72 (99th percentile) and multiple references are tagged Exploit, indicating public exploit code exists. No ransomware group usage is documented in the record.

What to do

  • Upgrade MiniShare to a version later than 1.4.1, or retire the product if no supported release exists.
  • If the server must remain, restrict access to trusted networks and block untrusted inbound traffic to its HTTP port.
  • Run the service under a low-privilege account and isolate it so code execution does not reach sensitive data or systems.
  • Monitor vendor and OSVDB patch references for any backported fix and apply it promptly.

Detection

  • Inspect HTTP server logs for abnormally long GET request lines or oversized request URIs targeting the MiniShare port.
  • Alert on MiniShare process crashes or restarts, which can indicate overflow attempts.
  • Watch for unexpected child processes or outbound connections originating from the MiniShare host after HTTP requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-2271 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2004-2271), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.