Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

184 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)11%—Lighttpd6/3/200616/6/2026
response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space characters, which are ignored by Windows, as demonstrated by PHP files.
ModificadaMedia (5)1.5%—Raidenhttpd6/3/200616/6/2026
RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests involving (1) "." (dot), (2) space, and (3) "/" (slash) characters.
ModificadaBaja (2.6)2.2%—Lighttpd18/2/200616/6/2026
LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for…
ModificadaBaja (2.1)0.37%—Acme Labs Thttpd6/11/200516/6/2026
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.
ModificadaMedia (6.4)5.6%—An-httpd2/5/200516/6/2026
Buffer overflow in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to execute arbitrary code via an HTTP request with a long User-Agent header.
ModificadaMedia (6.4)2.3%—An-httpd7/4/200516/6/2026
CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.
ModificadaAlta (7.5)3.1%—Raidenhttpd1/3/200516/6/2026
Buffer overflow in RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to execute arbitrary code via a long URL.
ModificadaMedia (5)1.5%—Raidenhttpd1/3/200516/6/2026
RaidenHTTPD 1.1.32, and possibly other versions before 1.1.34, allows remote attackers to view the PHP source code via an HTTP GET request for a filename with a trailing (1) . (dot) or (2) space.
ModificadaMedia (5)1.7%—Lighttpd16/2/200516/6/2026
The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the source code for CGI and FastCGI scripts via a URL with a %00 (null) character after the file extension.
ModificadaAlta (10)5.6%—Cherokee Httpd10/1/200516/6/2026
Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.
ModificadaMedia (4.3)1.4%—FreescoAIThttpdAI31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter.
ModificadaMedia (4.3)3.6%—Cherokee Httpd31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly quoted in the resulting error page.
ModificadaAlta (7.5)10%—Omnicron OmnihttpdAI31/12/200416/6/2026
Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header.
ModificadaMedia (4.3)1.8%—Mephistoles Internet Suite Mephistoles Httpd31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Mephistoles httpd 0.6.0 final allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into the URL.
ModificadaMedia (5)3.6%—Acme Labs Thttpd31/12/200416/6/2026
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").
ModificadaMedia (5)3.2%—JIM Rees HttpdShaun2k2 Palmhttpd23/11/200416/6/2026
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP connections, which exceeds the PalmOS accept queue.
ModificadaMedia (4.6)0.58%—Cherokee Httpd19/4/200416/6/2026
Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at…
ModificadaMedia (5)1.6%—Cherokee Httpd26/12/200316/6/2026
connection.c in Cherokee web server before 0.4.6 allows remote attackers to cause a denial of service via an HTTP POST request without a Content-Length header field.
ModificadaCrítica (9.8)22%—Acme Thttpd3/11/200316/6/2026
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.
ModificadaMedia (5)6.8%—Charles Steinkuehler Sh-httpd27/10/200316/6/2026
Charles Steinkuehler sh-httpd 0.3 and 0.4 allows remote attackers to read files or execute arbitrary CGI scripts via a GET request that contains an asterisk (*) wildcard character.
ModificadaMedia (4.3)3.9%—Omnicron Omnihttpd9/6/200316/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in OmniHTTPd allow remote attackers to insert script or HTML into web pages via (1) test.php, (2) test.shtml, or (3) redir.exe.
ModificadaMedia (5)2.8%—Acme Labs Thttpd12/5/200316/6/2026
Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.
ModificadaAlta (7.5)23%—Nulllogic Null Httpd2/4/200316/6/2026
Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a negative value in the Content-Length HTTP header.
ModificadaMedia (4.3)1.7%—Nulllogic Null Httpd2/4/200316/6/2026
Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitrary HTML into a "404 Not Found" response.
ModificadaAlta (7.5)11%—Light Httpd31/3/200316/6/2026
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.