Записи lighttpd
36 опубликованных записей вендора lighttpd.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 88,9 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-399 Resource Management Errors4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-416 Use After Free2
- CWE-326 Inadequate Encryption Strength1
- CWE-401 Missing Release of Memory after Effective Lifetime1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
36 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2019-11072Эксплойта нет | lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) orlighttpd · lighttpd · CWE-190 | Критическая9,8 | — | 73,8 % | 10 апр. 2019 г. |
58В плане | CVE-2014-2323Proof of concept | SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via thelighttpd · lighttpd · CWE-89 | Критическая9,8 | — | 62,8 % | 14 мар. 2014 г. |
47В плане | CVE-2022-30780Proof of concept | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because conneclighttpd · lighttpd · CWE-682 | Высокая7,5 | — | 56,9 % | 11 июн. 2022 г. |
34Наблюдать | CVE-2018-19052Proof of concept | An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50.lighttpd · lighttpd · CWE-22 | Высокая7,5 | — | 13,7 % | 7 нояб. 2018 г. |
34Наблюдать | CVE-2007-3949Эксплойта нет | mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny selighttpd · lighttpd | Высокая8,3 | — | 3,3 % | 23 июл. 2007 г. |
33Наблюдать | CVE-2013-4559Эксплойта нет | lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpdlighttpd · lighttpd · CWE-264 | Высокая7,6 | — | 10,7 % | 20 нояб. 2013 г. |
33Наблюдать | CVE-2015-3200Эксплойта нет | mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a lighttpd · lighttpd · CWE-74 | Высокая7,5 | — | 9,9 % | 9 июн. 2015 г. |
32Наблюдать | CVE-2007-1870Эксплойта нет | lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NUlighttpd · lighttpd | Высокая7,8 | — | 2,7 % | 17 апр. 2007 г. |
31Наблюдать | CVE-2007-4727Эксплойта нет | Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows relighttpd · lighttpd · CWE-119 | Средняя6,8 | — | 12,9 % | 12 сент. 2007 г. |
31Наблюдать | CVE-2008-4359Эксплойта нет | lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL delighttpd · lighttpd · CWE-200 | Высокая7,5 | — | 4,3 % | 3 окт. 2008 г. |
31Наблюдать | CVE-2008-4360Эксплойта нет | mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons olighttpd · lighttpd · CWE-200 | Высокая7,5 | — | 4,3 % | 3 окт. 2008 г. |
31Наблюдать | CVE-2022-41556Эксплойта нет | A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a larlighttpd · lighttpd · CWE-401 | Высокая7,5 | — | 2,9 % | 6 окт. 2022 г. |
31Наблюдать | CVE-2013-4508Эксплойта нет | lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by ilighttpd · lighttpd · CWE-326 | Высокая7,5 | — | 2,6 % | 8 нояб. 2013 г. |
31Наблюдать | CVE-2022-37797Эксплойта нет | In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is receivedlighttpd · lighttpd · CWE-476 | Высокая7,5 | — | 2,5 % | 12 сент. 2022 г. |
29Наблюдать | CVE-2014-2324Proof of concept | Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to lighttpd · lighttpd · CWE-22 | Средняя5,0 | — | 28,8 % | 14 мар. 2014 г. |
27Наблюдать | CVE-2025-12642Эксплойта нет | HTTP Header Smuggling via Trailer Mergelighttpd · lighttpd · CWE-444 | Средняя6,9 | — | 0,3 % | 3 нояб. 2025 г. |
26Наблюдать | CVE-2011-4362Proof of concept | Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 lighttpd · lighttpd | Средняя5,0 | — | 21,1 % | 24 дек. 2011 г. |
26Наблюдать | CVE-2022-22707Эксплойта нет | In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 blighttpd · lighttpd · CWE-787 | Средняя5,9 | — | 8,9 % | 6 янв. 2022 г. |
26Наблюдать | CVE-2007-3946Эксплойта нет | mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectorslighttpd · lighttpd | Средняя6,4 | — | 3,4 % | 23 июл. 2007 г. |
25Наблюдать | CVE-2007-3947Proof of concept | request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate hlighttpd · lighttpd | Средняя5,8 | — | 8,1 % | 23 июл. 2007 г. |
24Наблюдать | CVE-2010-0295Proof of concept | lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to calighttpd · lighttpd · CWE-399 | Средняя5,0 | — | 12,1 % | 3 февр. 2010 г. |
24Наблюдать | CVE-2012-5533Proof of concept | The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite lighttpd · lighttpd · CWE-399 | Средняя5,0 | — | 12,0 % | 24 нояб. 2012 г. |
24Наблюдать | CVE-2008-1270Proof of concept | mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to realighttpd · lighttpd · CWE-200 | Средняя5,0 | — | 11,9 % | 10 мар. 2008 г. |
23Наблюдать | CVE-2006-0814Эксплойта нет | response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code vialighttpd · lighttpd | Средняя5,0 | — | 10,6 % | 6 мар. 2006 г. |
22Наблюдать | CVE-2013-4560Эксплойта нет | Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) vlighttpd · lighttpd · CWE-416 | Средняя5,0 | — | 5,4 % | 20 нояб. 2013 г. |
- CVE-2019-1107261На этой неделе
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or
КритическаяCVSS 9,8Эксплойта нетEPSS 74 %lighttpd · lighttpd10 апр. 2019 г.
- CVE-2014-232358В плане
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the
КритическаяCVSS 9,8Proof of conceptEPSS 63 %lighttpd · lighttpd14 мар. 2014 г.
- CVE-2022-3078047В плане
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connec
ВысокаяCVSS 7,5Proof of conceptEPSS 57 %lighttpd · lighttpd11 июн. 2022 г.
- CVE-2018-1905234Наблюдать
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50.
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %lighttpd · lighttpd7 нояб. 2018 г.
- CVE-2007-394934Наблюдать
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny se
ВысокаяCVSS 8,3Эксплойта нетEPSS 3 %lighttpd · lighttpd23 июл. 2007 г.
- CVE-2013-455933Наблюдать
lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd
ВысокаяCVSS 7,6Эксплойта нетEPSS 11 %lighttpd · lighttpd20 нояб. 2013 г.
- CVE-2015-320033Наблюдать
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %lighttpd · lighttpd9 июн. 2015 г.
- CVE-2007-187032Наблюдать
lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NU
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %lighttpd · lighttpd17 апр. 2007 г.
- CVE-2007-472731Наблюдать
Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows re
СредняяCVSS 6,8Эксплойта нетEPSS 13 %lighttpd · lighttpd12 сент. 2007 г.
- CVE-2008-435931Наблюдать
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL de
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %lighttpd · lighttpd3 окт. 2008 г.
- CVE-2008-436031Наблюдать
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons o
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %lighttpd · lighttpd3 окт. 2008 г.
- CVE-2022-4155631Наблюдать
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a lar
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %lighttpd · lighttpd6 окт. 2022 г.
- CVE-2013-450831Наблюдать
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by i
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %lighttpd · lighttpd8 нояб. 2013 г.
- CVE-2022-3779731Наблюдать
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %lighttpd · lighttpd12 сент. 2022 г.
- CVE-2014-232429Наблюдать
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to
СредняяCVSS 5,0Proof of conceptEPSS 29 %lighttpd · lighttpd14 мар. 2014 г.
- CVE-2025-1264227Наблюдать
HTTP Header Smuggling via Trailer Merge
СредняяCVSS 6,9Эксплойта нетEPSS 0 %lighttpd · lighttpd3 нояб. 2025 г.
- CVE-2011-436226Наблюдать
Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30
СредняяCVSS 5,0Proof of conceptEPSS 21 %lighttpd · lighttpd24 дек. 2011 г.
- CVE-2022-2270726Наблюдать
In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 b
СредняяCVSS 5,9Эксплойта нетEPSS 9 %lighttpd · lighttpd6 янв. 2022 г.
- CVE-2007-394626Наблюдать
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors
СредняяCVSS 6,4Эксплойта нетEPSS 3 %lighttpd · lighttpd23 июл. 2007 г.
- CVE-2007-394725Наблюдать
request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate h
СредняяCVSS 5,8Proof of conceptEPSS 8 %lighttpd · lighttpd23 июл. 2007 г.
- CVE-2010-029524Наблюдать
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to ca
СредняяCVSS 5,0Proof of conceptEPSS 12 %lighttpd · lighttpd3 февр. 2010 г.
- CVE-2012-553324Наблюдать
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite
СредняяCVSS 5,0Proof of conceptEPSS 12 %lighttpd · lighttpd24 нояб. 2012 г.
- CVE-2008-127024Наблюдать
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to rea
СредняяCVSS 5,0Proof of conceptEPSS 12 %lighttpd · lighttpd10 мар. 2008 г.
- CVE-2006-081423Наблюдать
response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via
СредняяCVSS 5,0Эксплойта нетEPSS 11 %lighttpd · lighttpd6 мар. 2006 г.
- CVE-2013-456022Наблюдать
Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) v
СредняяCVSS 5,0Эксплойта нетEPSS 5 %lighttpd · lighttpd20 нояб. 2013 г.