Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lighttpd CRITICAL 9.1
CVE-2025-12642

lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smugg…

Patch available
Fix from $2,300 2025-11-03
Lighttpd HIGH 7.5
CVE-2022-30780EPSS 56%

Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read…

Patch available
Fix from $1,950 2022-06-11
Lighttpd CRITICAL 9.8
CVE-2019-11072EPSS 74%

lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly…

Fix: after 1.4.53
Fix from $2,300 2019-04-10
Lighttpd HIGH 7.5
CVE-2015-3200EPSS 10%

mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon cha…

Fix: after 15.07
Fix from $1,950 2015-06-09
Lighttpd MEDIUM 5.0
CVE-2012-5533EPSS 12%

The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via…

Patch available
Fix from $1,600 2012-11-24
Lighttpd MEDIUM 5.0
CVE-2010-0295EPSS 12%

lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a den…

Fix: after 1.4.25
Fix from $1,600 2010-02-03
Lighttpd MEDIUM 5.0
CVE-2008-4298

Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory co…

Fix: after 1.4.19
Fix from $1,600 2008-09-27
Lighttpd MEDIUM 5.0
CVE-2008-1270EPSS 12%

mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitra…

Fix: after 1.4.18
Fix from $1,600 2008-03-10
Lighttpd MEDIUM 5.0
CVE-2008-1111

mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers…

Mitigation only
Fix from $1,600 2008-03-04
Lighttpd MEDIUM 5.0
CVE-2008-0983

lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attac…

Patch available
Fix from $1,600 2008-02-26
Lighttpd MEDIUM 6.8
CVE-2007-4727EPSS 13%

Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote atta…

Fix: after 1.4.15
Fix from $1,600 2007-09-12
Lighttpd HIGH 8.3
CVE-2007-3949

mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.

Fix: after 1.4.15
Fix from $1,950 2007-07-24
Lighttpd MEDIUM 6.4
CVE-2007-3946

mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involvin…

Fix: after 1.4.15
Fix from $1,600 2007-07-24
Lighttpd MEDIUM 5.8
CVE-2007-3947EPSS 8%

request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, a…

Fix: after 1.4.15
Fix from $1,600 2007-07-24
Lighttpd HIGH 7.8
CVE-2007-1870

lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NULL pointe…

Patch available
Fix from $1,950 2007-04-18
Lighttpd MEDIUM 5.0
CVE-2007-1869

lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is par…

Patch available
Fix from $1,600 2007-04-18
Lighttpd MEDIUM 5.0
CVE-2006-0814EPSS 10%

response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests…

Patch available
Fix from $1,600 2006-03-06
Lighttpd MEDIUM 5.0
CVE-2005-0453

The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the …

Patch available
Fix from $1,600 2005-02-16