Acme maintains a narrow but prominent portfolio of lightweight HTTP server products—thttpd, mini_httpd, micro_httpd, and ultra_mini_httpd—that see deployment in embedded systems, IoT devices, and resource-constrained environments where their minimal footprint is valued. Vulnerabilities affecting these servers skew strongly toward critical severity and frequently acquire public exploit code, with the recurring exposure centered on input validation weaknesses, buffer-boundary violations, code injection, and information-disclosure flaws that are characteristic of C-based network services handling untrusted request data. Defenders should treat updates to this vendor's products as security-relevant, particularly in inventory spanning embedded and IoT assets; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Acme over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18778MEDIUM ACME mini_httpd before 1.30 lets remote users read arbitrary files. | Oct 29, 2018 | 6.5 | 73 | NO | YES |
CVE-2003-0899CRITICAL Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger t | Nov 3, 2003 | 9.8 | 53 | NO | YES |
CVE-2014-4927HIGH Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (cras | Jul 24, 2014 | 7.8 | 41 | NO | YES |
CVE-2009-4491CRITICAL thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary co | Jan 13, 2010 | 9.8 | 41 | NO | YES |
CVE-2007-0158CRITICAL thttpd 2007 has buffer underflow. | Dec 27, 2019 | 9.8 | 31 | NO | NO |
CVE-2001-1496CRITICAL Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | Dec 31, 2001 | 9.8 | 31 | NO | NO |
CVE-2009-4490MEDIUM mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary | Jan 13, 2010 | 5.0 | 30 | NO | YES |
CVE-2017-17663CRITICAL The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution. | Feb 6, 2018 | 9.8 | 29 | NO | NO |
CVE-2010-1544MEDIUM micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80. | Apr 26, 2010 | 5.0 | 24 | NO | YES |
CVE-2024-0263HIGH A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipula | Jan 7, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acme.
Media articles that mention a CVE ID that affects a product developed by Acme — matched by CVE ID, not by vendor name.