Записи ACME
15 опубликованных записей вендора acme.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 40 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-668 Exposure of Resource to Wrong Sphere2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-404 Improper Resource Shutdown or Release1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
15 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
47В плане | CVE-2018-18778Proof of concept | ACME mini_httpd before 1.30 lets remote users read arbitrary files.acme · mini-httpd · CWE-200 | Средняя6,5 | — | 70,8 % | 29 окт. 2018 г. |
46В плане | CVE-2003-0899Proof of concept | Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contaiacme · thttpd · CWE-131 | Критическая9,8 | — | 22,2 % | 3 нояб. 2003 г. |
43В плане | CVE-2009-4491Proof of concept | thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window'sacme · thttpd · CWE-20 | Критическая9,8 | — | 13,7 % | 13 янв. 2010 г. |
40В плане | CVE-2001-1496Эксплойта нет | Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of servicacme · thttpd · CWE-193 | Критическая9,8 | — | 4,8 % | 31 дек. 2001 г. |
40В плане | CVE-2017-17663Эксплойта нет | The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remacme · mini httpd · CWE-119 | Критическая9,8 | — | 2,7 % | 6 февр. 2018 г. |
39Наблюдать | CVE-2007-0158Эксплойта нет | thttpd 2007 has buffer underflow.acme · thttpd · CWE-787 | Критическая9,8 | — | 1,3 % | 27 дек. 2019 г. |
34Наблюдать | CVE-2014-4927Proof of concept | Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attaacme · micro httpd · CWE-119 | Высокая7,8 | — | 11,2 % | 24 июл. 2014 г. |
30Наблюдать | CVE-2024-0263Эксплойта нет | ACME Ultra Mini HTTPd HTTP GET Request denial of serviceacme · ultra mini httpd · CWE-404 | Высокая7,5 | — | 1,4 % | 7 янв. 2024 г. |
23Наблюдать | CVE-2009-4490Proof of concept | mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a windowacme · mini httpd · CWE-20 | Средняя5,0 | — | 10,2 % | 13 янв. 2010 г. |
22Наблюдать | CVE-2012-5640Эксплойта нет | thttpd has a local DoS vulnerability via specially-crafted .htpasswd filesacme · thttpd · CWE-476 | Средняя5,5 | — | 0,4 % | 25 нояб. 2019 г. |
21Наблюдать | CVE-2010-1544Proof of concept | micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP portrca · digital cable modem · CWE-20 | Средняя5,0 | — | 2,6 % | 26 апр. 2010 г. |
21Наблюдать | CVE-2001-0893Эксплойта нет | Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request wiacme · mini httpd · CWE-668 | Средняя5,0 | — | 2,5 % | 13 нояб. 2001 г. |
21Наблюдать | CVE-2001-0892Эксплойта нет | Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the documentacme · thttpd · CWE-668 | Средняя5,0 | — | 1,9 % | 13 нояб. 2001 г. |
20Наблюдать | CVE-2015-1548Эксплойта нет | mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long protacme · mini httpd · CWE-119 | Средняя5,0 | — | 1,6 % | 10 февр. 2015 г. |
8Наблюдать | CVE-2013-0348Эксплойта нет | thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obopen source development team · sthttpd · CWE-264 | Низкая2,1 | — | 0,5 % | 13 дек. 2013 г. |
- CVE-2018-1877847В плане
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
СредняяCVSS 6,5Proof of conceptEPSS 71 %acme · mini-httpd29 окт. 2018 г.
- CVE-2003-089946В плане
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contai
КритическаяCVSS 9,8Proof of conceptEPSS 22 %acme · thttpd3 нояб. 2003 г.
- CVE-2009-449143В плане
thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's
КритическаяCVSS 9,8Proof of conceptEPSS 14 %acme · thttpd13 янв. 2010 г.
- CVE-2001-149640В плане
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of servic
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %acme · thttpd31 дек. 2001 г.
- CVE-2017-1766340В плане
The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited rem
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %acme · mini httpd6 февр. 2018 г.
- CVE-2007-015839Наблюдать
thttpd 2007 has buffer underflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %acme · thttpd27 дек. 2019 г.
- CVE-2014-492734Наблюдать
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote atta
ВысокаяCVSS 7,8Proof of conceptEPSS 11 %acme · micro httpd24 июл. 2014 г.
- CVE-2024-026330Наблюдать
ACME Ultra Mini HTTPd HTTP GET Request denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %acme · ultra mini httpd7 янв. 2024 г.
- CVE-2009-449023Наблюдать
mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window
СредняяCVSS 5,0Proof of conceptEPSS 10 %acme · mini httpd13 янв. 2010 г.
- CVE-2012-564022Наблюдать
thttpd has a local DoS vulnerability via specially-crafted .htpasswd files
СредняяCVSS 5,5Эксплойта нетEPSS 0 %acme · thttpd25 нояб. 2019 г.
- CVE-2010-154421Наблюдать
micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port
СредняяCVSS 5,0Proof of conceptEPSS 3 %rca · digital cable modem26 апр. 2010 г.
- CVE-2001-089321Наблюдать
Acme mini_httpd before 1.16 allows remote attackers to view sensitive files under the document root (such as .htpasswd) via a GET request wi
СредняяCVSS 5,0Эксплойта нетEPSS 3 %acme · mini httpd13 нояб. 2001 г.
- CVE-2001-089221Наблюдать
Acme Thttpd Secure Webserver before 2.22, with the chroot option enabled, allows remote attackers to view sensitive files under the document
СредняяCVSS 5,0Эксплойта нетEPSS 2 %acme · thttpd13 нояб. 2001 г.
- CVE-2015-154820Наблюдать
mini_httpd 1.21 and earlier allows remote attackers to obtain sensitive information from process memory via an HTTP request with a long prot
СредняяCVSS 5,0Эксплойта нетEPSS 2 %acme · mini httpd10 февр. 2015 г.
- CVE-2013-03488Наблюдать
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to ob
НизкаяCVSS 2,1Эксплойта нетEPSS 1 %open source development team · sthttpd13 дек. 2013 г.