Vulnerability record · CVE-2013-5019 · published 31 July 2013
CVE-2013-5019: Ultra Mini HTTPD stack buffer overflow via long resource name
Vector · Ultra Mini Httpd
Ultra Mini HTTPD 1.21 contains a stack-based buffer overflow (CWE-119) triggered by a long resource name in an HTTP request. A remote, unauthenticated attacker can send a crafted request to corrupt memory and potentially execute arbitrary code on the host running the web server.
Description
Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP request.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityRemote, unauthenticated code execution with complete impact and public exploit code plus very high EPSS probability makes this an urgent exposure for any host still running the affected version.
What it is
Ultra Mini HTTPD 1.21 contains a stack-based buffer overflow (CWE-119) triggered by a long resource name in an HTTP request. A remote, unauthenticated attacker can send a crafted request to corrupt memory and potentially execute arbitrary code on the host running the web server.
Impact
Successful exploitation can give the attacker arbitrary code execution with the privileges of the HTTPD process, leading to full compromise of the affected service and host. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.
Attack surface
Reachable over the network through the HTTP listener; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host exposing Ultra Mini HTTPD 1.21 to untrusted networks is exposed.
Exploitation
Not listed in CISA KEV, but public Exploit-DB entries exist (tags: Exploit) and EPSS is 0.63572 (99.176th percentile), indicating high likelihood of exploitation activity.
What to do
- Upgrade or replace Ultra Mini HTTPD 1.21 with a maintained web server; no fixed version is stated in this record, so verify vendor guidance before relying on a patch.
- If the product cannot be replaced, restrict network access to the HTTP listener with firewall rules or a reverse proxy that filters oversized or malformed request paths.
- Deploy an application-layer filter or WAF rule that rejects HTTP requests with abnormally long resource names.
- Run the HTTPD process under a low-privilege account and isolate it to limit post-exploitation impact.
- Monitor vendor and Exploit-DB references for updated remediation guidance.
Detection
- Inspect HTTP server and proxy logs for requests with unusually long or malformed resource names/URIs.
- Alert on crashes, restarts or abnormal termination of the Ultra Mini HTTPD process.
- Monitor for unexpected child processes or outbound connections spawned by the web server process.
- Use network IDS signatures for known Exploit-DB PoCs targeting this buffer overflow.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-5019 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-5019), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.