Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

184 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.0%—Nakata AN Httpd31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in AN HTTP 1.41d allows remote attackers to inject arbitrary web script or HTML via a colon (:) in the query string, which is inserted into the resulting error page.
ModificadaAlta (7.5)5.6%—Gaztek Ghttpd31/12/200216/6/2026
Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaAlta (10)7.6%—Hughes Technologies Libhttpd31/12/200216/6/2026
Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP POST request.
ModificadaCrítica (9.8)9.0%—Redshift Atphttpd31/12/200216/6/2026
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
ModificadaMedia (6.4)1.8%—Tinyhttpd31/12/200216/6/2026
Directory traversal vulnerability in TinyHTTPD 0.1 .0 allows remote attackers to read or execute arbitrary files via a ".." (dot dot) in the URL.
ModificadaAlta (7.5)5.5%—An-httpd31/12/200216/6/2026
Buffer overflow in AN HTTPd 1.38 through 1.4.1c allows remote attackers to execute arbitrary code via a SOCKS4 request with a long username.
ModificadaMedia (5)2.0%—Perl-httpd31/12/200216/6/2026
Directory traversal vulnerability in Perl-HTTPd before 1.0.2 allows remote attackers to view arbitrary files via a .. (dot dot) in an unknown argument.
ModificadaMedia (5)1.6%—Omnicron Omnihttpd4/10/200216/6/2026
Omnicron OmniHTTPd 2.09 allows remote attackers to cause a denial of service (crash) via an HTTP request with a long, malformed HTTP 1version number.
ModificadaAlta (7.5)8.0%—Acme Labs Thttpd12/8/200216/6/2026
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.
ModificadaMedia (4.3)3.9%—W3C Cern Httpd12/8/200216/6/2026
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error page.
ModificadaCrítica (9.8)4.8%—Acme Thttpd31/12/200116/6/2026
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaAlta (7.5)3.4%—Cherokee Httpd29/12/200116/6/2026
Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.
ModificadaAlta (7.8)4.1%—Cherokee Httpd29/12/200116/6/2026
Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
ModificadaMedia (5)1.9%—Acme Thttpd13/11/200116/6/2026
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
ModificadaMedia (5)2.5%—Acme Mini Httpd13/11/200116/6/2026
Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
ModificadaMedia (5)6.3%—Omnicron Omnihttpd18/10/200116/6/2026
OmniHTTPd 2.0.8 and earlier allow remote attackers to obtain source code via a GET request with the URL-encoded symbol for a space (%20).
ModificadaMedia (5)1.7%—Omnicron Omnihttpd18/10/200116/6/2026
Omnicron OmniHTTPd 2.0.8 allows remote attackers to cause a denial of service (memory exhaustion) via a series of requests for PHP scripts.
ModificadaMedia (5)1.7%—Omnicron Omnihttpd22/8/200116/6/2026
Omnicron Technologies OmniHTTPD Professional 2.08 and earlier allows a remote attacker to create a denial of service via a long POST URL request.
ModificadaMedia (5)1.6%—Doug Neal Dnhttpd3/7/200116/6/2026
Directory traversal vulnerability in Doug Neal's HTTPD Daemon (DNHTTPD) before 0.4.1 allows remote attackers to view arbitrary files via a .. (dot dot) attack using the dot hex code '%2E'.
ModificadaMedia (5)2.2%—Omnicron Omnihttpd12/3/200116/6/2026
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to overwrite arbitrary files via the cgidir parameter.
ModificadaAlta (10)10%—Omnicron Omnihttpd12/3/200116/6/2026
statsconfig.pl in OmniHTTPd 2.07 allows remote attackers to execute arbitrary commands via the mostbrowsers parameter, whose value is used as part of a generated Perl script.
ModificadaAlta (7.5)2.0%—Acme Labs Thttpd19/12/200023/9/2026
Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.
ModificadaAlta (10)5.5%—Acme Labs Thttpd20/10/200016/6/2026
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.
ModificadaAlta (7.5)2.0%—W3C Cern Httpd18/1/200016/6/2026
The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.
ModificadaMedia (5)1.7%—Thttpd Http Server31/12/199916/6/2026
thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.