Thttpd

Vendor:

First CVE: Oct 20, 2000 · Active for 25 years

10
Total CVEs
More Total CVEs than 88% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Thttpd over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Feb 2, 2007
7,115 days ago

CVE Severity & Scoring

Thttpd10 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local1 (10.0%)
Network0 (0.0%)
Unknown9 (90.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (10.0%)
High0 (0.0%)
Unknown9 (90.0%)
User Interaction
None1 (10.0%)
Unknown9 (90.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (10.0%)
Unknown9 (90.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the
Aug 12, 20027.531NOYES
Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-enco
Dec 31, 20045.029NOYES
Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.
Oct 20, 200010.026NONO
Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command l
Mar 9, 20068.421NONO
htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, w
Mar 9, 20067.220NONO
Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.
May 12, 20035.020NONO
Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot do
Dec 19, 20007.520NONO
thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.
Oct 31, 20067.218NONO
thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.
Feb 2, 20075.016NONO
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.
Nov 6, 20052.111NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
20.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Thttpd

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.25b37.60.4%00
2.23b112.10.4%00
2.21b12.10.4%00
2.20b17.58.0%01
2.1917.52.0%00
2.1817.52.0%00
2.1717.52.0%00
2.1617.52.0%00
2.0.7_beta_0.415.03.6%01
2.0.4110.05.4%00
2.0.3110.05.4%00
2.0.2110.05.4%00
2.0.1110.05.4%00
2.0110.05.4%00
1.95110.05.4%00
1.90a110.05.4%00