Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
184 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 11% | — | Lighttpd | 6/3/2006 | 16/6/2026 | response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space characters, which are ignored by Windows, as demonstrated by PHP files. | |
| Modificada | Media (5) | 1.5% | — | Raidenhttpd | 6/3/2006 | 16/6/2026 | RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests involving (1) "." (dot), (2) space, and (3) "/" (slash) characters. | |
| Modificada | Baja (2.6) | 2.2% | — | Lighttpd | 18/2/2006 | 16/6/2026 | LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for… | |
| Modificada | Baja (2.1) | 0.37% | — | Acme Labs Thttpd | 6/11/2005 | 16/6/2026 | syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file. | |
| Modificada | Media (6.4) | 5.6% | — | An-httpd | 2/5/2005 | 16/6/2026 | Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header. | |
| Modificada | Media (6.4) | 2.3% | — | An-httpd | 7/4/2005 | 16/6/2026 | CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request. | |
| Modificada | Alta (7.5) | 3.1% | — | Raidenhttpd | 1/3/2005 | 16/6/2026 | Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL. | |
| Modificada | Media (5) | 1.5% | — | Raidenhttpd | 1/3/2005 | 16/6/2026 | RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space. | |
| Modificada | Media (5) | 1.7% | — | Lighttpd | 16/2/2005 | 16/6/2026 | The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension. | |
| Modificada | Alta (10) | 5.6% | — | Cherokee Httpd | 10/1/2005 | 16/6/2026 | Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL. | |
| Modificada | Media (4.3) | 1.4% | — | FreescoAIThttpdAI | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter. | |
| Modificada | Media (4.3) | 3.6% | — | Cherokee Httpd | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page. | |
| Modificada | Alta (7.5) | 10% | — | Omnicron OmnihttpdAI | 31/12/2004 | 16/6/2026 | Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header. | |
| Modificada | Media (4.3) | 1.8% | — | Mephistoles Internet Suite Mephistoles Httpd | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the URL. | |
| Modificada | Media (5) | 3.6% | — | Acme Labs Thttpd | 31/12/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:"). | |
| Modificada | Media (5) | 3.2% | — | JIM Rees HttpdShaun2k2 Palmhttpd | 23/11/2004 | 16/6/2026 | palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue. | |
| Modificada | Media (4.6) | 0.58% | — | Cherokee Httpd | 19/4/2004 | 16/6/2026 | Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at… | |
| Modificada | Media (5) | 1.6% | — | Cherokee Httpd | 26/12/2003 | 16/6/2026 | connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field. | |
| Modificada | Crítica (9.8) | 22% | — | Acme Thttpd | 3/11/2003 | 16/6/2026 | Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences. | |
| Modificada | Media (5) | 6.8% | — | Charles Steinkuehler Sh-httpd | 27/10/2003 | 16/6/2026 | Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character. | |
| Modificada | Media (4.3) | 3.9% | — | Omnicron Omnihttpd | 9/6/2003 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe. | |
| Modificada | Media (5) | 2.8% | — | Acme Labs Thttpd | 12/5/2003 | 16/6/2026 | Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header. | |
| Modificada | Alta (7.5) | 23% | — | Nulllogic Null Httpd | 2/4/2003 | 16/6/2026 | Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header. | |
| Modificada | Media (4.3) | 1.7% | — | Nulllogic Null Httpd | 2/4/2003 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found" response. | |
| Modificada | Alta (7.5) | 11% | — | Light Httpd | 31/3/2003 | 16/6/2026 | Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request. |