V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
Filters

All vulnerabilities

39 / 39
Product: debian:lighttpd×Clear all
3.4
CVE-2014-3566DEB
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterminist…
2014-01-01Pre-auth
EPSS100.0%
pct 100
9.8
CVE-2009-3555DEB
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet …
2009-01-01Pre-auth
EPSS87.3%
pct 99
9.8
CVE-2019-11072DEB
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cau…
2019-01-01Pre-auth
EPSS73.8%
pct 99
4.3
CVE-2011-3389ANC
The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet…
2011-01-01
EPSS73.3%
pct 99
9.8
CVE-2014-2323DEB
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attack…
2014-01-01Pre-auth
EPSS61.7%
pct 99
7.5
CVE-2022-30780DEB
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consu…
2022-01-01Pre-auth
EPSS56.4%
pct 98
5.0
CVE-2014-2324DEB
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in ligh…
2014-01-01
EPSS28.8%
pct 97
5.0
CVE-2011-4362DEB
Integer signedness error in the base64_decode function in the HTTP authentication functionality…
2011-01-01
EPSS16.2%
pct 96
7.5
CVE-2018-19052DEB
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50.…
2018-01-01Pre-auth
EPSS14.1%
pct 96
6.8
CVE-2007-4727DEB
Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi …
2007-01-01
EPSS12.9%
pct 95
5.0
CVE-2010-0295DEB
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a…
2010-01-01
EPSS12.1%
pct 95
5.0
CVE-2012-5533DEB
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote atta…
2012-01-01
EPSS12.0%
pct 95
5.0
CVE-2008-1270DEB
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HO…
2008-01-01
EPSS11.9%
pct 95
7.6
CVE-2013-4559DEB
lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) se…
2013-01-01
EPSS10.7%
pct 95
7.5
CVE-2015-3200DEB
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via …
2015-01-01Pre-auth
EPSS10.0%
pct 94
5.9
CVE-2022-22707DEB
In lighttpd 1.4.46 through 1.4.63, the mod_extforward_Forwarded function of the mod_extforward …
2022-01-01Pre-auth
EPSS9.0%
pct 94
5.8
CVE-2007-3947DEB
request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash…
2007-01-01
EPSS8.1%
pct 94
5.0
CVE-2013-4560DEB
Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denia…
2013-01-01
EPSS5.4%
pct 91
7.5
CVE-2008-4360DEB
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem i…
2008-01-01
EPSS4.3%
pct 89
7.5
CVE-2008-4359DEB
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite co…
2008-01-01
EPSS4.3%
pct 89
4.3
CVE-2012-4929ANC
The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other prod…
2012-01-01
EPSS4.3%
pct 89
5.0
CVE-2008-4298DEB
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows re…
2008-01-01
EPSS3.5%
pct 87
6.4
CVE-2007-3946DEB
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of s…
2007-01-01
EPSS3.4%
pct 87
5.0
CVE-2007-1869DEB
lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resour…
2007-01-01
EPSS3.4%
pct 87
4.3
CVE-2008-1531DEB
The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x…
2008-01-01
EPSS3.4%
pct 87
8.3
CVE-2007-3949DEB
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows …
2007-01-01
EPSS3.3%
pct 86
4.3
CVE-2007-3950DEB
lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of ser…
2007-01-01
EPSS2.9%
pct 85
4.3
CVE-2007-3948DEB
connections.c in lighttpd before 1.4.16 might accept more connections than the configured maxim…
2007-01-01
EPSS2.9%
pct 85
7.5
CVE-2022-41556DEB
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of ser…
2022-01-01Pre-auth
EPSS2.7%
pct 84
7.8
CVE-2007-1870DEB
lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a…
2007-01-01
EPSS2.7%
pct 84
7.5
CVE-2013-4508DEB
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier…
2013-01-01Pre-auth
EPSS2.6%
pct 83
5.0
CVE-2008-0983DEB
lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size…
2008-01-01
EPSS2.3%
pct 81
5.0
CVE-2008-1111DEB
mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a f…
2008-01-01
EPSS2.0%
pct 78
7.5
CVE-2022-37797DEB
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid H…
2022-01-01Pre-auth
EPSS1.9%
pct 77
5.0
CVE-2014-2469DEB
Unspecified vulnerability in lighttpd in Oracle Solaris 11.1 allows attackers to cause a denial…
2014-01-01
EPSS1.9%
pct 76
5.3
CVE-2018-25103ANC
There exists use-after-free vulnerabilities in lighttpd <= 1.4.50 request parsing which might r…
2018-01-01Pre-auth
EPSS0.7%
pct 46
1.9
CVE-2013-1427DEB
The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Lin…
2013-01-01
EPSS0.3%
pct 26
6.9
CVE-2025-12642DEB
lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This …
2025-01-01Pre-auth
EPSS0.3%
pct 21
0.0
CVE-2016-1000212DEB
Mitigation for HTTPoxy vulnerability
2016-01-01
EPSS0.0%
pct 0
Select a vulnerability on the left to open the preview.