Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Acme

First CVE: Nov 13, 2001Active for: 25 yearsTotal CVEs: 15
45.2
VTI Score
High

Acme maintains a narrow but prominent portfolio of lightweight HTTP server products—thttpd, mini_httpd, micro_httpd, and ultra_mini_httpd—that see deployment in embedded systems, IoT devices, and resource-constrained environments where their minimal footprint is valued. Vulnerabilities affecting these servers skew strongly toward critical severity and frequently acquire public exploit code, with the recurring exposure centered on input validation weaknesses, buffer-boundary violations, code injection, and information-disclosure flaws that are characteristic of C-based network services handling untrusted request data. Defenders should treat updates to this vendor's products as security-relevant, particularly in inventory spanning embedded and IoT assets; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Acme over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 13, 2001
24 years ago
Most Recent CVE
Jan 7, 2024
929 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-18778MEDIUM
ACME mini_httpd before 1.30 lets remote users read arbitrary files.
Oct 29, 20186.573NOYES
CVE-2003-0899CRITICAL
Buffer overflow in defang in libhttpd.c for thttpd 2.21 to 2.23b1 allows remote attackers to execute arbitrary code via requests that contain '<' or '>' characters, which trigger t
Nov 3, 20039.853NOYES
CVE-2014-4927HIGH
Buffer overflow in ACME micro_httpd, as used in D-Link DSL2750U and DSL2740U and NetGear WGR614 and MR-ADSL-DG834 routers allows remote attackers to cause a denial of service (cras
Jul 24, 20147.841NOYES
CVE-2009-4491CRITICAL
thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary co
Jan 13, 20109.841NOYES
CVE-2007-0158CRITICAL
thttpd 2007 has buffer underflow.
Dec 27, 20199.831NONO
CVE-2001-1496CRITICAL
Off-by-one buffer overflow in Basic Authentication in Acme Labs thttpd 1.95 through 2.20 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Dec 31, 20019.831NONO
CVE-2009-4490MEDIUM
mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary
Jan 13, 20105.030NOYES
CVE-2017-17663CRITICAL
The htpasswd implementation of mini_httpd before v1.28 and of thttpd before v2.28 is affected by a buffer overflow that can be exploited remotely to perform code execution.
Feb 6, 20189.829NONO
CVE-2010-1544MEDIUM
micro_httpd on the RCA DCM425 cable modem allows remote attackers to cause a denial of service (device reboot) via a long string to TCP port 80.
Apr 26, 20105.024NOYES
CVE-2024-0263HIGH
A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipula
Jan 7, 20247.521NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
47%
13%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (6.7%)
Network7 (46.7%)
Unknown7 (46.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (53.3%)
High0 (0.0%)
Unknown7 (46.7%)
User Interaction
None8 (53.3%)
Unknown7 (46.7%)
Required0 (0.0%)
Privileges Required
Low2 (13.3%)
High0 (0.0%)
None6 (40.0%)
Unknown7 (46.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
6.7% of CVEs· 96th percentile
ExploitDB
5 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Acme.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Acme — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Acme's Products

View all 3 CNAs →

Top CWEs