Acme Labs
Acme Labs Thttpd: vulnerabilidades y CVE
Acme Labs Thttpd tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2007-0664 | Media (5) | 2.9% | — | 2 feb 2007 | thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files. |
| CVE-2006-4248 | Alta (7.2) | 0.38% | — | 31 oct 2006 | thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file. |
| CVE-2006-1079 | Alta (7.2) | 0.40% | — | 9 mar 2006 | htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system… |
| CVE-2006-1078 | Alta (8.4) | 0.54% | — | 9 mar 2006 | Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a… |
| CVE-2005-3124 | Baja (2.1) | 0.37% | — | 6 nov 2005 | syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file. |
| CVE-2004-2628 | Media (5) | 3.6% | — | 31 dic 2004 | Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence… |
| CVE-2002-1562 | Media (5) | 2.8% | — | 12 may 2003 | Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header. |
| CVE-2002-0733 | Alta (7.5) | 8.0% | — | 12 ago 2002 | Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message. |
| CVE-2000-0900 | Alta (7.5) | 2.0% | — | 19 dic 2000 | Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack. |
| CVE-2000-0359 | Alta (10) | 5.5% | — | 20 oct 2000 | Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header. |