Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.4)0.54%—Acme Labs Thttpd9/3/200616/6/2026
Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through…
ModificadaAlta (7.2)0.40%—Acme Labs Thttpd9/3/200616/6/2026
htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is…
ModificadaMedia (4.3)1.5%—Acme Labs Perlcal11/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter.
ModificadaBaja (2.1)0.37%—Acme Labs Thttpd6/11/200516/6/2026
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.
ModificadaMedia (5)3.6%💥 ExploitAcme Labs Thttpd31/12/200416/6/2026
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").
ModificadaCrítica (9.8)22%💥 ExploitAcme Thttpd3/11/200316/6/2026
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.
ModificadaMedia (5)2.8%—Acme Labs Thttpd12/5/200316/6/2026
Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.
ModificadaAlta (7.5)8.0%💥 ExploitAcme Labs Thttpd12/8/200216/6/2026
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.
ModificadaCrítica (9.8)4.8%—Acme Thttpd31/12/200116/6/2026
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaMedia (5)2.5%—Acme Mini Httpd13/11/200116/6/2026
Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
ModificadaMedia (5)1.9%—Acme Thttpd13/11/200116/6/2026
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
ModificadaMedia (5)9.2%💥 ExploitAcme Labs Acme Server18/10/200116/6/2026
Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI.
ModificadaMedia (5)3.8%💥 ExploitAcme Labs Perlcal27/6/200116/6/2026
Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.
ModificadaAlta (7.5)2.0%—Acme Labs Thttpd19/12/200023/9/2026
Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.
ModificadaAlta (10)5.5%—Acme Labs Thttpd20/10/200016/6/2026
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.
Orbitaley — Vulnerabilidades