Skip to content
Noroxi

lighttpd records

36 published records for vendor lighttpd.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
88.9%
Median publish → KEV
No record has entered KEV

All records

36 records
  • CVE-2019-11072
    61This week

    lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or

    CriticalCVSS 9.8No exploitEPSS 74%

    lighttpd · lighttpdApr 10, 2019

  • SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the

    CriticalCVSS 9.8Proof of conceptEPSS 63%

    lighttpd · lighttpdMar 14, 2014

  • Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connec

    HighCVSS 7.5Proof of conceptEPSS 57%

    lighttpd · lighttpdJun 11, 2022

  • An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50.

    HighCVSS 7.5Proof of conceptEPSS 14%

    lighttpd · lighttpdNov 7, 2018

  • CVE-2007-3949
    34Monitor

    mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny se

    HighCVSS 8.3No exploitEPSS 3%

    lighttpd · lighttpdJul 23, 2007

  • CVE-2013-4559
    33Monitor

    lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd

    HighCVSS 7.6No exploitEPSS 11%

    lighttpd · lighttpdNov 20, 2013

  • CVE-2015-3200
    33Monitor

    mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a

    HighCVSS 7.5No exploitEPSS 10%

    lighttpd · lighttpdJun 9, 2015

  • CVE-2007-1870
    32Monitor

    lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NU

    HighCVSS 7.8No exploitEPSS 3%

    lighttpd · lighttpdApr 17, 2007

  • CVE-2007-4727
    31Monitor

    Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows re

    MediumCVSS 6.8No exploitEPSS 13%

    lighttpd · lighttpdSep 12, 2007

  • CVE-2008-4359
    31Monitor

    lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL de

    HighCVSS 7.5No exploitEPSS 4%

    lighttpd · lighttpdOct 3, 2008

  • CVE-2008-4360
    31Monitor

    mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons o

    HighCVSS 7.5No exploitEPSS 4%

    lighttpd · lighttpdOct 3, 2008

  • A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a lar

    HighCVSS 7.5No exploitEPSS 3%

    lighttpd · lighttpdOct 6, 2022

  • CVE-2013-4508
    31Monitor

    lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by i

    HighCVSS 7.5No exploitEPSS 3%

    lighttpd · lighttpdNov 8, 2013

  • In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received

    HighCVSS 7.5No exploitEPSS 3%

    lighttpd · lighttpdSep 12, 2022

  • CVE-2014-2324
    29Monitor

    Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to

    MediumCVSS 5.0Proof of conceptEPSS 29%

    lighttpd · lighttpdMar 14, 2014

  • HTTP Header Smuggling via Trailer Merge

    MediumCVSS 6.9No exploitEPSS 0%

    lighttpd · lighttpdNov 3, 2025

  • CVE-2011-4362
    26Monitor

    Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30

    MediumCVSS 5.0Proof of conceptEPSS 21%

    lighttpd · lighttpdDec 24, 2011

  • In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 b

    MediumCVSS 5.9No exploitEPSS 9%

    lighttpd · lighttpdJan 6, 2022

  • CVE-2007-3946
    26Monitor

    mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors

    MediumCVSS 6.4No exploitEPSS 3%

    lighttpd · lighttpdJul 23, 2007

  • CVE-2007-3947
    25Monitor

    request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate h

    MediumCVSS 5.8Proof of conceptEPSS 8%

    lighttpd · lighttpdJul 23, 2007

  • CVE-2010-0295
    24Monitor

    lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to ca

    MediumCVSS 5.0Proof of conceptEPSS 12%

    lighttpd · lighttpdFeb 3, 2010

  • CVE-2012-5533
    24Monitor

    The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite

    MediumCVSS 5.0Proof of conceptEPSS 12%

    lighttpd · lighttpdNov 24, 2012

  • CVE-2008-1270
    24Monitor

    mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to rea

    MediumCVSS 5.0Proof of conceptEPSS 12%

    lighttpd · lighttpdMar 10, 2008

  • CVE-2006-0814
    23Monitor

    response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via

    MediumCVSS 5.0No exploitEPSS 11%

    lighttpd · lighttpdMar 6, 2006

  • CVE-2013-4560
    22Monitor

    Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) v

    MediumCVSS 5.0No exploitEPSS 5%

    lighttpd · lighttpdNov 20, 2013