lighttpd records
36 published records for vendor lighttpd.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 88.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-399 Resource Management Errors4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-416 Use After Free2
- CWE-326 Inadequate Encryption Strength1
- CWE-401 Missing Release of Memory after Effective Lifetime1
The weakness classes this vendor ships most often: where to look.
CWEAll records
36 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2019-11072No exploit | lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) orlighttpd · lighttpd · CWE-190 | Critical9.8 | — | 73.8% | Apr 10, 2019 |
58Plan | CVE-2014-2323Proof of concept | SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via thelighttpd · lighttpd · CWE-89 | Critical9.8 | — | 62.8% | Mar 14, 2014 |
47Plan | CVE-2022-30780Proof of concept | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because conneclighttpd · lighttpd · CWE-682 | High7.5 | — | 56.9% | Jun 11, 2022 |
34Monitor | CVE-2018-19052Proof of concept | An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50.lighttpd · lighttpd · CWE-22 | High7.5 | — | 13.7% | Nov 7, 2018 |
34Monitor | CVE-2007-3949No exploit | mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny selighttpd · lighttpd | High8.3 | — | 3.3% | Jul 23, 2007 |
33Monitor | CVE-2013-4559No exploit | lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpdlighttpd · lighttpd · CWE-264 | High7.6 | — | 10.7% | Nov 20, 2013 |
33Monitor | CVE-2015-3200No exploit | mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a lighttpd · lighttpd · CWE-74 | High7.5 | — | 9.9% | Jun 9, 2015 |
32Monitor | CVE-2007-1870No exploit | lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NUlighttpd · lighttpd | High7.8 | — | 2.7% | Apr 17, 2007 |
31Monitor | CVE-2007-4727No exploit | Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows relighttpd · lighttpd · CWE-119 | Medium6.8 | — | 12.9% | Sep 12, 2007 |
31Monitor | CVE-2008-4359No exploit | lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL delighttpd · lighttpd · CWE-200 | High7.5 | — | 4.3% | Oct 3, 2008 |
31Monitor | CVE-2008-4360No exploit | mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons olighttpd · lighttpd · CWE-200 | High7.5 | — | 4.3% | Oct 3, 2008 |
31Monitor | CVE-2022-41556No exploit | A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a larlighttpd · lighttpd · CWE-401 | High7.5 | — | 2.9% | Oct 6, 2022 |
31Monitor | CVE-2013-4508No exploit | lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by ilighttpd · lighttpd · CWE-326 | High7.5 | — | 2.6% | Nov 8, 2013 |
31Monitor | CVE-2022-37797No exploit | In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is receivedlighttpd · lighttpd · CWE-476 | High7.5 | — | 2.5% | Sep 12, 2022 |
29Monitor | CVE-2014-2324Proof of concept | Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to lighttpd · lighttpd · CWE-22 | Medium5.0 | — | 28.8% | Mar 14, 2014 |
27Monitor | CVE-2025-12642No exploit | HTTP Header Smuggling via Trailer Mergelighttpd · lighttpd · CWE-444 | Medium6.9 | — | 0.3% | Nov 3, 2025 |
26Monitor | CVE-2011-4362Proof of concept | Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 lighttpd · lighttpd | Medium5.0 | — | 21.1% | Dec 24, 2011 |
26Monitor | CVE-2022-22707No exploit | In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 blighttpd · lighttpd · CWE-787 | Medium5.9 | — | 8.9% | Jan 6, 2022 |
26Monitor | CVE-2007-3946No exploit | mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectorslighttpd · lighttpd | Medium6.4 | — | 3.4% | Jul 23, 2007 |
25Monitor | CVE-2007-3947Proof of concept | request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate hlighttpd · lighttpd | Medium5.8 | — | 8.1% | Jul 23, 2007 |
24Monitor | CVE-2010-0295Proof of concept | lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to calighttpd · lighttpd · CWE-399 | Medium5.0 | — | 12.1% | Feb 3, 2010 |
24Monitor | CVE-2012-5533Proof of concept | The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite lighttpd · lighttpd · CWE-399 | Medium5.0 | — | 12.0% | Nov 24, 2012 |
24Monitor | CVE-2008-1270Proof of concept | mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to realighttpd · lighttpd · CWE-200 | Medium5.0 | — | 11.9% | Mar 10, 2008 |
23Monitor | CVE-2006-0814No exploit | response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code vialighttpd · lighttpd | Medium5.0 | — | 10.6% | Mar 6, 2006 |
22Monitor | CVE-2013-4560No exploit | Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) vlighttpd · lighttpd · CWE-416 | Medium5.0 | — | 5.4% | Nov 20, 2013 |
- CVE-2019-1107261This week
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or
CriticalCVSS 9.8No exploitEPSS 74%lighttpd · lighttpdApr 10, 2019
- CVE-2014-232358Plan
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the
CriticalCVSS 9.8Proof of conceptEPSS 63%lighttpd · lighttpdMar 14, 2014
- CVE-2022-3078047Plan
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connec
HighCVSS 7.5Proof of conceptEPSS 57%lighttpd · lighttpdJun 11, 2022
- CVE-2018-1905234Monitor
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50.
HighCVSS 7.5Proof of conceptEPSS 14%lighttpd · lighttpdNov 7, 2018
- CVE-2007-394934Monitor
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny se
HighCVSS 8.3No exploitEPSS 3%lighttpd · lighttpdJul 23, 2007
- CVE-2013-455933Monitor
lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd
HighCVSS 7.6No exploitEPSS 11%lighttpd · lighttpdNov 20, 2013
- CVE-2015-320033Monitor
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a
HighCVSS 7.5No exploitEPSS 10%lighttpd · lighttpdJun 9, 2015
- CVE-2007-187032Monitor
lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NU
HighCVSS 7.8No exploitEPSS 3%lighttpd · lighttpdApr 17, 2007
- CVE-2007-472731Monitor
Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows re
MediumCVSS 6.8No exploitEPSS 13%lighttpd · lighttpdSep 12, 2007
- CVE-2008-435931Monitor
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL de
HighCVSS 7.5No exploitEPSS 4%lighttpd · lighttpdOct 3, 2008
- CVE-2008-436031Monitor
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons o
HighCVSS 7.5No exploitEPSS 4%lighttpd · lighttpdOct 3, 2008
- CVE-2022-4155631Monitor
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a lar
HighCVSS 7.5No exploitEPSS 3%lighttpd · lighttpdOct 6, 2022
- CVE-2013-450831Monitor
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by i
HighCVSS 7.5No exploitEPSS 3%lighttpd · lighttpdNov 8, 2013
- CVE-2022-3779731Monitor
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received
HighCVSS 7.5No exploitEPSS 3%lighttpd · lighttpdSep 12, 2022
- CVE-2014-232429Monitor
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to
MediumCVSS 5.0Proof of conceptEPSS 29%lighttpd · lighttpdMar 14, 2014
- CVE-2025-1264227Monitor
HTTP Header Smuggling via Trailer Merge
MediumCVSS 6.9No exploitEPSS 0%lighttpd · lighttpdNov 3, 2025
- CVE-2011-436226Monitor
Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30
MediumCVSS 5.0Proof of conceptEPSS 21%lighttpd · lighttpdDec 24, 2011
- CVE-2022-2270726Monitor
In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 b
MediumCVSS 5.9No exploitEPSS 9%lighttpd · lighttpdJan 6, 2022
- CVE-2007-394626Monitor
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors
MediumCVSS 6.4No exploitEPSS 3%lighttpd · lighttpdJul 23, 2007
- CVE-2007-394725Monitor
request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate h
MediumCVSS 5.8Proof of conceptEPSS 8%lighttpd · lighttpdJul 23, 2007
- CVE-2010-029524Monitor
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to ca
MediumCVSS 5.0Proof of conceptEPSS 12%lighttpd · lighttpdFeb 3, 2010
- CVE-2012-553324Monitor
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite
MediumCVSS 5.0Proof of conceptEPSS 12%lighttpd · lighttpdNov 24, 2012
- CVE-2008-127024Monitor
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to rea
MediumCVSS 5.0Proof of conceptEPSS 12%lighttpd · lighttpdMar 10, 2008
- CVE-2006-081423Monitor
response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via
MediumCVSS 5.0No exploitEPSS 11%lighttpd · lighttpdMar 6, 2006
- CVE-2013-456022Monitor
Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) v
MediumCVSS 5.0No exploitEPSS 5%lighttpd · lighttpdNov 20, 2013