Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.54% | — | Acme Labs Thttpd | 9/3/2006 | 16/6/2026 | Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through… | |
| Modificada | Alta (7.2) | 0.40% | — | Acme Labs Thttpd | 9/3/2006 | 16/6/2026 | htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is… | |
| Modificada | Media (4.3) | 1.5% | — | Acme Labs Perlcal | 11/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter. | |
| Modificada | Baja (2.1) | 0.37% | — | Acme Labs Thttpd | 6/11/2005 | 16/6/2026 | syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Acme Labs Thttpd | 31/12/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:"). | |
| Modificada | Crítica (9.8) | 22% | 💥 Exploit | Acme Thttpd | 3/11/2003 | 16/6/2026 | Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences. | |
| Modificada | Media (5) | 2.8% | — | Acme Labs Thttpd | 12/5/2003 | 16/6/2026 | Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Acme Labs Thttpd | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message. | |
| Modificada | Crítica (9.8) | 4.8% | — | Acme Thttpd | 31/12/2001 | 16/6/2026 | Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (5) | 2.5% | — | Acme Mini Httpd | 13/11/2001 | 16/6/2026 | Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /. | |
| Modificada | Media (5) | 1.9% | — | Acme Thttpd | 13/11/2001 | 16/6/2026 | Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /. | |
| Modificada | Media (5) | 9.2% | 💥 Exploit | Acme Labs Acme Server | 18/10/2001 | 16/6/2026 | Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Acme Labs Perlcal | 27/6/2001 | 16/6/2026 | Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter. | |
| Modificada | Alta (7.5) | 2.0% | — | Acme Labs Thttpd | 19/12/2000 | 23/9/2026 | Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack. | |
| Modificada | Alta (10) | 5.5% | — | Acme Labs Thttpd | 20/10/2000 | 16/6/2026 | Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header. |