Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
184 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.2% | — | Raiden Professional Servers Raidenhttpd | 20/12/2007 | 16/6/2026 | Directory traversal vulnerability in raidenhttpd-admin/workspace.php in RaidenHTTPD 2.0.19, when the WebAdmin function is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the ulang parameter. | |
| Modificada | Media (6.4) | 2.7% | — | Shttpd | 17/12/2007 | 16/6/2026 | Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attackers to download arbitrary CGI programs or scripts via a URI with an appended (1) '+' character, (2) '.' character, (3) %2e sequence (hex-encoded dot), or (4) hex-encoded character greater than 0x7f. NOTE: the %20 vector is already… | |
| Modificada | Media (5) | 7.3% | — | Sergey Lyubka Simple Httpd | 13/12/2007 | 16/6/2026 | Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request that includes an MS-DOS device name, as demonstrated by the /aux URI. | |
| Modificada | Media (6.8) | 13% | — | Lighttpd | 12/9/2007 | 16/6/2026 | Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote attackers to overwrite arbitrary CGI variables and execute arbitrary code via an HTTP request with a long content length, as demonstrated by overwriting the SCRIPT_FILENAME… | |
| Modificada | Media (6.4) | 3.4% | — | Lighttpd | 24/7/2007 | 16/6/2026 | mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving (1) a memory leak, (2) use of md5-sess without a cnonce, (3) base64 encoded strings, and (4) trailing whitespace in the Auth-Digest header. | |
| Modificada | Media (4.3) | 2.9% | — | Lighttpd | 24/7/2007 | 16/6/2026 | connections.c in lighttpd before 1.4.16 might accept more connections than the configured maximum, which allows remote attackers to cause a denial of service (failed assertion) via a large number of connection attempts. | |
| Modificada | Media (4.3) | 2.9% | — | Lighttpd | 24/7/2007 | 16/6/2026 | lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving the use of incompatible format specifiers in certain debugging messages in the (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules. | |
| Modificada | Alta (8.3) | 3.3% | — | Lighttpd | 24/7/2007 | 16/6/2026 | mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings. | |
| Modificada | Media (5.8) | 8.1% | — | Lighttpd | 24/7/2007 | 16/6/2026 | request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, as demonstrated by a request containing two Location header lines, which results in a segmentation fault. | |
| Modificada | Media (4.3) | 1.3% | — | Kurinton Shttpd | 3/7/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Kurinton sHTTPd 20070408 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 8.4% | — | Sergey Lyubka Simple Httpd | 26/6/2007 | 16/6/2026 | Sergey Lyubka Simple HTTPD (shttpd) 1.38 allows remote attackers to obtain sensitive information (script source code) via a URL with a trailing encoded space (%20). | |
| Modificada | Media (4.3) | 1.3% | — | Raidenhttpd | 22/6/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in RaidenHTTPD before 2.0.14 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 3.4% | — | Lighttpd | 18/4/2007 | 16/6/2026 | lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is parsing CRLF sequences, which triggers an infinite loop and file descriptor consumption. | |
| Modificada | Alta (7.8) | 2.7% | — | Lighttpd | 18/4/2007 | 16/6/2026 | lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NULL pointer dereference. | |
| Modificada | Media (5) | 2.9% | — | Acme Labs Thttpd | 2/2/2007 | 16/6/2026 | thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files. | |
| Modificada | Alta (7.2) | 0.38% | — | Acme Labs Thttpd | 31/10/2006 | 16/6/2026 | thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file. | |
| Modificada | Alta (7.5) | 64% | — | Sergey Lyubka Simple Httpd | 10/10/2006 | 16/6/2026 | Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary code via a long URI. | |
| Modificada | Media (5) | 2.1% | — | Ohio State University OSU Httpd | 21/9/2006 | 16/6/2026 | OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL to a non-existent file, which displays the web root path in the resulting error message. | |
| Modificada | Media (5) | 2.2% | — | Ohio State University OSU Httpd | 21/9/2006 | 16/6/2026 | OSU 3.11alpha and 3.10a allows remote attackers to obtain sensitive information via a URL containing an * (asterisk) wildcard, which displays all matching file and directory information. | |
| Modificada | Media (5.1) | 2.6% | — | Raidenhttpd | 12/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in raidenhttpd-admin/slice/check.php in RaidenHTTPD 1.1.49, when register_globals and WebAdmin is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SoftParserFileXml parameter. | |
| Modificada | Media (5) | 4.0% | — | Norz Zawhttpd | 5/5/2006 | 16/6/2026 | Buffer overflow in zawhttpd 0.8.23, and possibly previous versions, allows remote attackers to cause a denial of service (daemon crash) via a request for a URI composed of several "\" (backslash) characters. | |
| Modificada | Media (4.3) | 6.8% | — | Cherokee Httpd | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cherokee HTTPD 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a malformed request that generates an HTTP 400 error, which is not properly handled when the error message is generated. | |
| Modificada | Alta (7.8) | 1.9% | — | An-httpd | 3/4/2006 | 16/6/2026 | AN HTTPD 1.42n, and possibly other versions before 1.42p, allows remote attackers to obtain source code of scripts via crafted requests with (1) dot and (2) space characters in the file extension. | |
| Modificada | Alta (7.2) | 0.40% | — | Acme Labs Thttpd | 9/3/2006 | 16/6/2026 | htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is… | |
| Modificada | Alta (8.4) | 0.54% | — | Acme Labs Thttpd | 9/3/2006 | 16/6/2026 | Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through… |