This CPE summary could be partial or incomplete. Please contact us for a detailed listing.
Summary
| Summuary | |
|---|---|
| CPE Name | cpe:/a:lighttpd:lighttpd |
| Detail | |||
|---|---|---|---|
| Vendor | Lighttpd | First view | 2005-02-16 |
| Product | Lighttpd | Last view | 2013-03-21 |
| Version | Type | Application | |
| Edition | |||
| Language | |||
| Update | |||
Activity : Yearly
COMMON PLATFORM ENUMERATION : Repartition per Version
| CPE Name | Affected CVE |
|---|---|
| cpe:/a:lighttpd:lighttpd:1.5.0 | 2 |
| cpe:/a:lighttpd:lighttpd:1.4.9 | 8 |
| cpe:/a:lighttpd:lighttpd:1.4.8 | 8 |
| cpe:/a:lighttpd:lighttpd:1.4.7 | 8 |
| cpe:/a:lighttpd:lighttpd:1.4.6 | 7 |
Related : CVE
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 1.9 | 2013-03-21 | CVE-2013-1427 | Local | Medium | None Requ... | |
| 5 | 2012-11-24 | CVE-2012-5533 | Network | Low | None Requ... | |
| 5 | 2011-12-24 | CVE-2011-4362 | Network | Low | None Requ... | |
| 5 | 2010-02-03 | CVE-2010-0295 | Network | Low | None Requ... | |
| 7.8 | 2008-10-03 | CVE-2008-4360 | Network | Low | None Requ... | |
| Date | Alert | Access Vector | Access Complexity | Authentification | ||
|---|---|---|---|---|---|---|
| 7.5 | 2008-10-03 | CVE-2008-4359 | Network | Low | None Requ... | |
| 5 | 2008-09-27 | CVE-2008-4298 | Network | Low | None Requ... | |
| 4.3 | 2008-03-27 | CVE-2008-1531 | Network | Medium | None Requ... | |
| 5 | 2008-03-10 | CVE-2008-1270 | Network | Low | None Requ... | |
| 5 | 2008-03-04 | CVE-2008-1111 | Network | Low | None Requ... | |
| 5 | 2008-02-26 | CVE-2008-0983 | Network | Low | None Requ... | |
| 6.8 | 2007-09-12 | CVE-2007-4727 | Network | Medium | None Requ... | |
| 4.3 | 2007-07-23 | CVE-2007-3950 | Network | Medium | None Requ... | |
| 8.3 | 2007-07-23 | CVE-2007-3949 | Network | Medium | None Requ... | |
| 4.3 | 2007-07-23 | CVE-2007-3948 | Network | Medium | None Requ... | |
| 5.8 | 2007-07-23 | CVE-2007-3947 | Network | Medium | None Requ... | |
| 6.4 | 2007-07-23 | CVE-2007-3946 | Network | Low | None Requ... | |
| 7.8 | 2007-04-17 | CVE-2007-1870 | Network | Low | None Requ... | |
| 5 | 2007-04-17 | CVE-2007-1869 | Network | Low | None Requ... | |
| 5 | 2006-03-06 | CVE-2006-0814 | Network | Low | None Requ... | |
| 2.6 | 2006-02-17 | CVE-2006-0760 | Network | High | None Requ... | |
| 5 | 2005-02-16 | CVE-2005-0453 | Network | Low | None Requ... |
CWE : Common Weakness Enumeration
| % | id | Name |
|---|---|---|
| 40% (4) | CWE-399 | Resource Management Errors |
| 40% (4) | CWE-200 | Information Exposure |
| 10% (1) | CWE-189 | Numeric Errors |
| 10% (1) | CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 77366 | lighttpd src/http_auth.c base64_decode() Function Base64 Data Parsing Out-of-... |
| 62068 | lighttpd HTTP Session Memory Exhaustion Remote DoS |
| 48889 | lighttpd mod_userdir Filename Component Case Mismatch Remote Access Restricti... |
| 48886 | lighttpd url.redirect / url.rewrite URL Decoding Remote Security Bypass |
| 48682 | lighttpd request.c http_request_parse Function Memory Leak Remote DoS |
| id | Description |
|---|---|
| 43788 | lighttpd Cross-user Forced SSL Session Termination DoS |
| 43170 | lighttpd mod_userdir userdir.path Information Disclosure |
| 43169 | lighttpd mod_cgi Fork Failure CGI Source Disclosure |
| 42363 | lighttpd File Descriptor Array Connection Saturation Remote DoS |
| 38317 | lighttpd mod_auth (http_auth.c) Malformed Auth-Digest Header Remote DoS |
| 38316 | lighttpd mod_auth (http_auth.c) base64_decode Handling Remote DoS |
| 38315 | lighttpd mod_auth (http_auth.c) Malformed md5-sess Remote DoS |
| 38314 | lighttpd mod_auth (http_auth.c) Unspecified Memory Leak DoS |
| 38313 | lighttpd request.c Malformed HTTP Request Remote DoS |
| 38312 | lighttpd connections.c Connection Saturation Remote DoS |
| 38311 | lighttpd mod_access.c Crafted URL url.access-deny Bypass |
| 38310 | lighttpd mod_webdav Debug Message Format Specifier Unspecified DoS |
| 38309 | lighttpd mod_fastcgi Debug Message Format Specifier Unspecified DoS |
| 38308 | lighttpd mod_scgi Debug Message Format Specifier Unspecified DoS |
| 36933 | lighttpd mod_fastcgi HTTP Request Header Overflow |
| 34176 | lighttpd 0 mtime Null Pointer DoS |
| 34175 | lighttpd CRLF Processing DoS |
| 23542 | lighttpd on Windows Crafted Filename Request Script Source Disclosure |
| 23229 | lighttpd Unexpected Capitalization File Extension Request Source Disclosure |
| 13844 | lighttpd Null Byte Request CGI Script Source Code Disclosure |
ExploitDB Exploits
| id | Description |
|---|---|
| 22902 | lighttpd 1.4.31 Denial of Service PoC |
| 18295 | lighttpd Denial of Service Vulnerability PoC |








