Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.1
CVE-2025-12642
lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited to conduct HTTP Header Smugg…
Lighttpd
Patch available
HIGH 7.5
CVE-2022-30780EPSS 56%
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connection_read…
Lighttpd
Patch available
CRITICAL 9.8
CVE-2019-11072EPSS 74%
lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly…
Lighttpd
after 1.4.53
HIGH 7.5
CVE-2015-3200EPSS 10%
mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon cha…
Lighttpd
after 15.07
MEDIUM 5.0
CVE-2012-5533EPSS 12%
The http_request_split_value function in request.c in lighttpd before 1.4.32 allows remote attackers to cause a denial of service (infinite loop) via…
Lighttpd
Patch available
MEDIUM 5.0
CVE-2010-0295EPSS 12%
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a den…
Lighttpd
after 1.4.25
MEDIUM 5.0
CVE-2008-4298
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory co…
Lighttpd
after 1.4.19
MEDIUM 5.0
CVE-2008-1270EPSS 12%
mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitra…
Lighttpd
after 1.4.18
MEDIUM 5.0
CVE-2008-1111
mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers…
Lighttpd
Mitigation only
MEDIUM 5.0
CVE-2008-0983
lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attac…
Lighttpd
Patch available
MEDIUM 6.8
CVE-2007-4727EPSS 13%
Buffer overflow in the fcgi_env_add function in mod_proxy_backend_fastcgi.c in the mod_fastcgi extension in lighttpd before 1.4.18 allows remote atta…
Lighttpd
after 1.4.15
HIGH 8.3
CVE-2007-3949
mod_access.c in lighttpd 1.4.15 ignores trailing / (slash) characters in the URL, which allows remote attackers to bypass url.access-deny settings.
Lighttpd
after 1.4.15
MEDIUM 6.4
CVE-2007-3946
mod_auth (http_auth.c) in lighttpd before 1.4.16 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involvin…
Lighttpd
after 1.4.15
MEDIUM 5.8
CVE-2007-3947EPSS 8%
request.c in lighttpd 1.4.15 allows remote attackers to cause a denial of service (daemon crash) by sending an HTTP request with duplicate headers, a…
Lighttpd
after 1.4.15
HIGH 7.8
CVE-2007-1870
lighttpd before 1.4.14 allows attackers to cause a denial of service (crash) via a request to a file whose mtime is 0, which results in a NULL pointe…
Lighttpd
Patch available
MEDIUM 5.0
CVE-2007-1869
lighttpd 1.4.12 and 1.4.13 allows remote attackers to cause a denial of service (cpu and resource consumption) by disconnecting while lighttpd is par…
Lighttpd
Patch available
MEDIUM 5.0
CVE-2006-0814EPSS 10%
response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests…
Lighttpd
Patch available
MEDIUM 5.0
CVE-2005-0453
The buffer_urldecode function in Lighttpd 1.3.7 and earlier does not properly handle control characters, which allows remote attackers to obtain the …
Lighttpd
Patch available