lighttpd kayıtları
lighttpd üreticisine ait 36 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %88,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-399 Resource Management Errors4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-416 Use After Free2
- CWE-326 Inadequate Encryption Strength1
- CWE-401 Missing Release of Memory after Effective Lifetime1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
36 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2019-11072İstismar yok | lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) orlighttpd · lighttpd · CWE-190 | Kritik9,8 | — | %73,8 | 10 Nis 2019 |
58Planlayın | CVE-2014-2323Kavram kanıtı | SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via thelighttpd · lighttpd · CWE-89 | Kritik9,8 | — | %62,8 | 14 Mar 2014 |
47Planlayın | CVE-2022-30780Kavram kanıtı | Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because conneclighttpd · lighttpd · CWE-682 | Yüksek7,5 | — | %56,9 | 11 Haz 2022 |
34İzleyin | CVE-2018-19052Kavram kanıtı | An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50.lighttpd · lighttpd · CWE-22 | Yüksek7,5 | — | %13,7 | 7 Kas 2018 |
34İzleyin | CVE-2007-3949İstismar yok | mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny selighttpd · lighttpd | Yüksek8,3 | — | %3,3 | 23 Tem 2007 |
33İzleyin | CVE-2013-4559İstismar yok | lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpdlighttpd · lighttpd · CWE-264 | Yüksek7,6 | — | %10,7 | 20 Kas 2013 |
33İzleyin | CVE-2015-3200İstismar yok | mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a lighttpd · lighttpd · CWE-74 | Yüksek7,5 | — | %9,9 | 9 Haz 2015 |
32İzleyin | CVE-2007-1870İstismar yok | lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NUlighttpd · lighttpd | Yüksek7,8 | — | %2,7 | 17 Nis 2007 |
31İzleyin | CVE-2007-4727İstismar yok | Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows relighttpd · lighttpd · CWE-119 | Orta6,8 | — | %12,9 | 12 Eyl 2007 |
31İzleyin | CVE-2008-4359İstismar yok | lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL delighttpd · lighttpd · CWE-200 | Yüksek7,5 | — | %4,3 | 3 Eki 2008 |
31İzleyin | CVE-2008-4360İstismar yok | mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons olighttpd · lighttpd · CWE-200 | Yüksek7,5 | — | %4,3 | 3 Eki 2008 |
31İzleyin | CVE-2022-41556İstismar yok | A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a larlighttpd · lighttpd · CWE-401 | Yüksek7,5 | — | %2,9 | 6 Eki 2022 |
31İzleyin | CVE-2013-4508İstismar yok | lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by ilighttpd · lighttpd · CWE-326 | Yüksek7,5 | — | %2,6 | 8 Kas 2013 |
31İzleyin | CVE-2022-37797İstismar yok | In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is receivedlighttpd · lighttpd · CWE-476 | Yüksek7,5 | — | %2,5 | 12 Eyl 2022 |
29İzleyin | CVE-2014-2324Kavram kanıtı | Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to lighttpd · lighttpd · CWE-22 | Orta5,0 | — | %28,8 | 14 Mar 2014 |
27İzleyin | CVE-2025-12642İstismar yok | HTTP Header Smuggling via Trailer Mergelighttpd · lighttpd · CWE-444 | Orta6,9 | — | %0,3 | 3 Kas 2025 |
26İzleyin | CVE-2011-4362Kavram kanıtı | Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 lighttpd · lighttpd | Orta5,0 | — | %21,1 | 24 Ara 2011 |
26İzleyin | CVE-2022-22707İstismar yok | In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 blighttpd · lighttpd · CWE-787 | Orta5,9 | — | %8,9 | 6 Oca 2022 |
26İzleyin | CVE-2007-3946İstismar yok | mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectorslighttpd · lighttpd | Orta6,4 | — | %3,4 | 23 Tem 2007 |
25İzleyin | CVE-2007-3947Kavram kanıtı | request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate hlighttpd · lighttpd | Orta5,8 | — | %8,1 | 23 Tem 2007 |
24İzleyin | CVE-2010-0295Kavram kanıtı | lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to calighttpd · lighttpd · CWE-399 | Orta5,0 | — | %12,1 | 3 Şub 2010 |
24İzleyin | CVE-2012-5533Kavram kanıtı | The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite lighttpd · lighttpd · CWE-399 | Orta5,0 | — | %12,0 | 24 Kas 2012 |
24İzleyin | CVE-2008-1270Kavram kanıtı | mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to realighttpd · lighttpd · CWE-200 | Orta5,0 | — | %11,9 | 10 Mar 2008 |
23İzleyin | CVE-2006-0814İstismar yok | response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code vialighttpd · lighttpd | Orta5,0 | — | %10,6 | 6 Mar 2006 |
22İzleyin | CVE-2013-4560İstismar yok | Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) vlighttpd · lighttpd · CWE-416 | Orta5,0 | — | %5,4 | 20 Kas 2013 |
- CVE-2019-1107261Bu hafta
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or
KritikCVSS 9,8İstismar yokEPSS %74lighttpd · lighttpd10 Nis 2019
- CVE-2014-232358Planlayın
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the
KritikCVSS 9,8Kavram kanıtıEPSS %63lighttpd · lighttpd14 Mar 2014
- CVE-2022-3078047Planlayın
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connec
YüksekCVSS 7,5Kavram kanıtıEPSS %57lighttpd · lighttpd11 Haz 2022
- CVE-2018-1905234İzleyin
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50.
YüksekCVSS 7,5Kavram kanıtıEPSS %14lighttpd · lighttpd7 Kas 2018
- CVE-2007-394934İzleyin
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny se
YüksekCVSS 8,3İstismar yokEPSS %3lighttpd · lighttpd23 Tem 2007
- CVE-2013-455933İzleyin
lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd
YüksekCVSS 7,6İstismar yokEPSS %11lighttpd · lighttpd20 Kas 2013
- CVE-2015-320033İzleyin
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a
YüksekCVSS 7,5İstismar yokEPSS %10lighttpd · lighttpd9 Haz 2015
- CVE-2007-187032İzleyin
lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NU
YüksekCVSS 7,8İstismar yokEPSS %3lighttpd · lighttpd17 Nis 2007
- CVE-2007-472731İzleyin
Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows re
OrtaCVSS 6,8İstismar yokEPSS %13lighttpd · lighttpd12 Eyl 2007
- CVE-2008-435931İzleyin
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL de
YüksekCVSS 7,5İstismar yokEPSS %4lighttpd · lighttpd3 Eki 2008
- CVE-2008-436031İzleyin
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons o
YüksekCVSS 7,5İstismar yokEPSS %4lighttpd · lighttpd3 Eki 2008
- CVE-2022-4155631İzleyin
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a lar
YüksekCVSS 7,5İstismar yokEPSS %3lighttpd · lighttpd6 Eki 2022
- CVE-2013-450831İzleyin
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by i
YüksekCVSS 7,5İstismar yokEPSS %3lighttpd · lighttpd8 Kas 2013
- CVE-2022-3779731İzleyin
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received
YüksekCVSS 7,5İstismar yokEPSS %3lighttpd · lighttpd12 Eyl 2022
- CVE-2014-232429İzleyin
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to
OrtaCVSS 5,0Kavram kanıtıEPSS %29lighttpd · lighttpd14 Mar 2014
- CVE-2025-1264227İzleyin
HTTP Header Smuggling via Trailer Merge
OrtaCVSS 6,9İstismar yokEPSS %0lighttpd · lighttpd3 Kas 2025
- CVE-2011-436226İzleyin
Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30
OrtaCVSS 5,0Kavram kanıtıEPSS %21lighttpd · lighttpd24 Ara 2011
- CVE-2022-2270726İzleyin
In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward plugin has a stack-based buffer overflow (4 b
OrtaCVSS 5,9İstismar yokEPSS %9lighttpd · lighttpd6 Oca 2022
- CVE-2007-394626İzleyin
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors
OrtaCVSS 6,4İstismar yokEPSS %3lighttpd · lighttpd23 Tem 2007
- CVE-2007-394725İzleyin
request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate h
OrtaCVSS 5,8Kavram kanıtıEPSS %8lighttpd · lighttpd23 Tem 2007
- CVE-2010-029524İzleyin
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to ca
OrtaCVSS 5,0Kavram kanıtıEPSS %12lighttpd · lighttpd3 Şub 2010
- CVE-2012-553324İzleyin
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite
OrtaCVSS 5,0Kavram kanıtıEPSS %12lighttpd · lighttpd24 Kas 2012
- CVE-2008-127024İzleyin
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to rea
OrtaCVSS 5,0Kavram kanıtıEPSS %12lighttpd · lighttpd10 Mar 2008
- CVE-2006-081423İzleyin
response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via
OrtaCVSS 5,0İstismar yokEPSS %11lighttpd · lighttpd6 Mar 2006
- CVE-2013-456022İzleyin
Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) v
OrtaCVSS 5,0İstismar yokEPSS %5lighttpd · lighttpd20 Kas 2013