Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
184 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 12% | — | Lighttpd | 24/11/2012 | 16/6/2026 | The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via a request with a header containing an empty token, as demonstrated using the "Connection: TE,,Keep-Alive" header. | |
| Modificada | Media (5) | 1.2% | — | Dhttpd | 27/12/2011 | 16/6/2026 | dhttpd allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris. | |
| Modificada | Media (5) | 21% | — | LighttpdDebian Linux | 24/12/2011 | 16/6/2026 | Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service (segmentation fault) via crafted base64 input that triggers an out-of-bounds read with a… | |
| Modificada | Alta (7.5) | 13% | — | ShttpdValenok MongooseYasslews | 5/8/2011 | 16/6/2026 | Stack-based buffer overflow in the (1) put_dir function in mongoose.c in Mongoose 3.0, (2) put_dir function in yasslEWS.c in yaSSL Embedded Web Server (yasslEWS) 0.2, and (3) _shttpd_put_dir function in io_dir.c in Simple HTTPD (shttpd) 1.42 allows remote attackers to execute arbitrary code via an HTTP PUT request, as… | |
| Modificada | Media (5) | 2.4% | — | Eterna Bozohttpd | 2/8/2010 | 16/6/2026 | bozotic HTTP server (aka bozohttpd) before 20100621 allows remote attackers to list the contents of home directories, and determine the existence of user accounts, via multiple requests for URIs beginning with /~ sequences. | |
| Modificada | Media (5) | 1.7% | — | Eterna Bozohttpd | 2/8/2010 | 16/6/2026 | bozotic HTTP server (aka bozohttpd) 20090522 through 20100512 allows attackers to cause a denial of service via vectors related to a "wrong code generation interaction with GCC." | |
| Modificada | Media (5) | 2.6% | — | Acme Micro HttpdRCA Digital Cable Modem | 26/4/2010 | 16/6/2026 | micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80. | |
| Modificada | Alta (7.5) | 1.3% | — | Jasper Httpdx | 20/4/2010 | 16/6/2026 | The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makes it easier for remote attackers to obtain privileged access. | |
| Modificada | Alta (9.3) | 38% | — | Jasper Httpdx | 20/4/2010 | 16/6/2026 | Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute… | |
| Modificada | Media (5) | 12% | — | Lighttpd | 3/2/2010 | 16/6/2026 | lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate. | |
| Modificada | Crítica (9.8) | 14% | — | Acme Thttpd | 13/1/2010 | 16/6/2026 | thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |
| Modificada | Media (5) | 10% | — | Acme Mini Httpd | 13/1/2010 | 16/6/2026 | mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |
| Modificada | Media (5) | 7.1% | — | Jasper Httpdx | 31/12/2009 | 16/6/2026 | httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI. | |
| Modificada | Media (5) | 3.5% | — | Cherokee Httpd | 6/11/2009 | 16/6/2026 | Directory traversal vulnerability in Cherokee Web Server 0.5.4 and earlier for Windows allows remote attackers to read arbitrary files via a /\.. (slash backslash dot dot) in the URL. | |
| Modificada | Alta (10) | 64% | — | Jasper Httpdx | 16/10/2009 | 16/6/2026 | Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (10) | 15% | — | Jasper Httpdx | 11/10/2009 | 16/6/2026 | Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the Host header. | |
| Modificada | Media (5) | 2.6% | — | Fhttpd | 19/8/2009 | 16/6/2026 | fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after the Basic value. | |
| Modificada | Alta (7.5) | 4.3% | — | LighttpdDebian Linux | 3/10/2008 | 16/6/2026 | mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to bypass intended access restrictions, as demonstrated by a request for a .PHP file when there… | |
| Modificada | Alta (7.5) | 4.3% | — | LighttpdDebian Linux | 3/10/2008 | 16/6/2026 | lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and obtain sensitive information or possibly modify data. | |
| Modificada | Media (5) | 3.5% | — | Lighttpd | 27/9/2008 | 16/6/2026 | Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers. | |
| Modificada | Media (4.3) | 3.4% | — | LighttpdDebian Linux | 27/3/2008 | 16/6/2026 | The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as disconnecting before a download has finished, which causes all active SSL connections to be… | |
| Modificada | Media (5) | 12% | — | Lighttpd | 10/3/2008 | 16/6/2026 | mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory. | |
| Modificada | Media (5) | 2.0% | — | Lighttpd | 4/3/2008 | 16/6/2026 | mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information. | |
| Modificada | Media (5) | 2.3% | — | Lighttpd | 26/2/2008 | 16/6/2026 | lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access. | |
| Modificada | Media (4.3) | 1.1% | — | Raidenhttpd | 6/2/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in RaidenHTTPD 2.0.19 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the ulang parameter. |