Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.95% | — | Geovision Gv-lpc2011AIGeovision Gv-lpc2211AIThttpdAI | 26/6/2026 | 26/6/2026 | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by… | |
| Modificada | Alta (7.5) | 1.4% | — | Sthttpd Project Sthttpd | 7/2/2021 | 17/6/2026 | An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this… | |
| Modificada | Crítica (9.8) | 1.3% | — | Acme Thttpd | 27/12/2019 | 16/6/2026 | thttpd 2007 has buffer underflow. | |
| Modificada | Media (5.5) | 0.39% | — | Acme Thttpd | 25/11/2019 | 16/6/2026 | thttpd has a local DoS vulnerability via specially-crafted .htpasswd files | |
| Modificada | Crítica (9.8) | 2.7% | — | Acme Mini HttpdAcme Thttpd | 6/2/2018 | 17/6/2026 | The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution. | |
| Modificada | Alta (7.8) | 1.5% | — | Sthttpd Project Sthttpd | 29/6/2017 | 17/6/2026 | Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename. | |
| Modificada | Baja (2.1) | 0.52% | — | Open Source Development Team SthttpdFedoraproject FedoraGentoo LinuxOpensuse+1 | 13/12/2013 | 16/6/2026 | thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file. | |
| Modificada | Crítica (9.8) | 14% | — | Acme Thttpd | 13/1/2010 | 16/6/2026 | thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | |
| Modificada | Media (5) | 2.9% | — | Acme Labs Thttpd | 2/2/2007 | 16/6/2026 | thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files. | |
| Modificada | Alta (7.2) | 0.38% | — | Acme Labs Thttpd | 31/10/2006 | 16/6/2026 | thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file. | |
| Modificada | Alta (7.2) | 0.40% | — | Acme Labs Thttpd | 9/3/2006 | 16/6/2026 | htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is… | |
| Modificada | Alta (8.4) | 0.54% | — | Acme Labs Thttpd | 9/3/2006 | 16/6/2026 | Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through… | |
| Modificada | Baja (2.1) | 0.37% | — | Acme Labs Thttpd | 6/11/2005 | 16/6/2026 | syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file. | |
| Modificada | Media (4.3) | 1.4% | — | FreescoAIThttpdAI | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter. | |
| Modificada | Media (5) | 3.6% | — | Acme Labs Thttpd | 31/12/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:"). | |
| Modificada | Crítica (9.8) | 22% | — | Acme Thttpd | 3/11/2003 | 16/6/2026 | Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "<" and ">" sequences. | |
| Modificada | Media (5) | 2.8% | — | Acme Labs Thttpd | 12/5/2003 | 16/6/2026 | Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header. | |
| Modificada | Alta (7.5) | 8.0% | — | Acme Labs Thttpd | 12/8/2002 | 16/6/2026 | Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message. | |
| Modificada | Crítica (9.8) | 4.8% | — | Acme Thttpd | 31/12/2001 | 16/6/2026 | Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (5) | 1.9% | — | Acme Thttpd | 13/11/2001 | 16/6/2026 | Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /. | |
| Modificada | Alta (7.5) | 2.0% | — | Acme Labs Thttpd | 19/12/2000 | 23/9/2026 | Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack. | |
| Modificada | Alta (10) | 5.5% | — | Acme Labs Thttpd | 20/10/2000 | 16/6/2026 | Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header. | |
| Modificada | Media (5) | 1.7% | — | Thttpd Http Server | 31/12/1999 | 16/6/2026 | thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename. | |
| Modificada | Alta (7.5) | 1.8% | — | Thttpd Http Server | 16/11/1999 | 16/6/2026 | Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function. |