Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2734▲ 30 respecto a la semana anterior
Críticas / altas1469▲ 361 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.95%—Geovision Gv-lpc2011AIGeovision Gv-lpc2211AIThttpdAI26/6/202626/6/2026
An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote attacker may exploit this vulnerability by…
ModificadaAlta (7.5)1.4%—Sthttpd Project Sthttpd7/2/202117/6/2026
An issue was discovered in sthttpd through 2.27.1. On systems where the strcpy function is implemented with memcpy, the de_dotdot function may cause a Denial-of-Service (daemon crash) due to overlapping memory ranges being passed to memcpy. This can triggered with an HTTP GET request for a crafted filename. NOTE: this…
ModificadaCrítica (9.8)1.3%—Acme Thttpd27/12/201916/6/2026
thttpd 2007 has buffer underflow.
ModificadaMedia (5.5)0.39%—Acme Thttpd25/11/201916/6/2026
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files
ModificadaCrítica (9.8)2.7%—Acme Mini HttpdAcme Thttpd6/2/201817/6/2026
The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution.
ModificadaAlta (7.8)1.5%—Sthttpd Project Sthttpd29/6/201717/6/2026
Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename.
ModificadaBaja (2.1)0.52%—Open Source Development Team SthttpdFedoraproject FedoraGentoo LinuxOpensuse+113/12/201316/6/2026
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
ModificadaCrítica (9.8)14%—Acme Thttpd13/1/201016/6/2026
thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.
ModificadaMedia (5)2.9%—Acme Labs Thttpd2/2/200716/6/2026
thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.
ModificadaAlta (7.2)0.38%—Acme Labs Thttpd31/10/200616/6/2026
thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.
ModificadaAlta (7.2)0.40%—Acme Labs Thttpd9/3/200616/6/2026
htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is…
ModificadaAlta (8.4)0.54%—Acme Labs Thttpd9/3/200616/6/2026
Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through…
ModificadaBaja (2.1)0.37%—Acme Labs Thttpd6/11/200516/6/2026
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.
ModificadaMedia (4.3)1.4%—FreescoAIThttpdAI31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to inject arbitrary web script or HTML via the test parameter.
ModificadaMedia (5)3.6%—Acme Labs Thttpd31/12/200416/6/2026
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot-dot sequence ("%5C..") or (2) a drive letter (such as "C:").
ModificadaCrítica (9.8)22%—Acme Thttpd3/11/200316/6/2026
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger the overflow when the characters are expanded to "&lt;" and "&gt;" sequences.
ModificadaMedia (5)2.8%—Acme Labs Thttpd12/5/200316/6/2026
Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.
ModificadaAlta (7.5)8.0%—Acme Labs Thttpd12/8/200216/6/2026
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 404 error message.
ModificadaCrítica (9.8)4.8%—Acme Thttpd31/12/200116/6/2026
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaMedia (5)1.9%—Acme Thttpd13/11/200116/6/2026
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request with a trailing /.
ModificadaAlta (7.5)2.0%—Acme Labs Thttpd19/12/200023/9/2026
Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.
ModificadaAlta (10)5.5%—Acme Labs Thttpd20/10/200016/6/2026
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.
ModificadaMedia (5)1.7%—Thttpd Http Server31/12/199916/6/2026
thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.
ModificadaAlta (7.5)1.8%—Thttpd Http Server16/11/199916/6/2026
Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.