Acme Labs maintains a small portfolio of lightweight web-serving and utility applications including thttpd, PerlCal, and ACME Server, which occupy a modest but durable presence in infrastructure deployments. Despite limited product scope, vulnerabilities affecting these tools frequently acquire public exploit code, driven by the accessibility of web-facing and scripting-heavy components and recurrent input-validation weaknesses. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Acme Labs over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0733HIGH Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the | Aug 12, 2002 | 7.5 | 31 | NO | YES |
CVE-2004-2628MEDIUM Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-enco | Dec 31, 2004 | 5.0 | 29 | NO | YES |
CVE-2001-0463MEDIUM Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter. | Jun 27, 2001 | 5.0 | 29 | NO | YES |
CVE-2001-0748MEDIUM Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI. | Oct 18, 2001 | 5.0 | 28 | NO | YES |
CVE-2000-0359HIGH Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header. | Oct 20, 2000 | 10.0 | 26 | NO | NO |
CVE-2006-1078HIGH Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command l | Mar 9, 2006 | 8.4 | 21 | NO | NO |
CVE-2006-1079HIGH htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, w | Mar 9, 2006 | 7.2 | 20 | NO | NO |
CVE-2002-1562MEDIUM Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header. | May 12, 2003 | 5.0 | 20 | NO | NO |
CVE-2000-0900HIGH Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot do | Dec 19, 2000 | 7.5 | 20 | NO | NO |
CVE-2006-4248HIGH thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file. | Oct 31, 2006 | 7.2 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Acme Labs.
Media articles that mention a CVE ID that affects a product developed by Acme Labs — matched by CVE ID, not by vendor name.