Thttpd
Vendor:
First CVE: Oct 20, 2000 · Active for 25 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Thttpd over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 20, 2000
25 years ago
Most Recent CVE
Feb 2, 2007
7,115 days ago
CVE Severity & Scoring
Thttpd10 CVEs
10%
30%
60%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (10.0%)
Network0 (0.0%)
Unknown9 (90.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (10.0%)
High0 (0.0%)
Unknown9 (90.0%)
User Interaction
None1 (10.0%)
Unknown9 (90.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (10.0%)
Unknown9 (90.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0733HIGH Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the | Aug 12, 2002 | 7.5 | 31 | NO | YES |
CVE-2004-2628MEDIUM Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-enco | Dec 31, 2004 | 5.0 | 29 | NO | YES |
CVE-2000-0359HIGH Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header. | Oct 20, 2000 | 10.0 | 26 | NO | NO |
CVE-2006-1078HIGH Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command l | Mar 9, 2006 | 8.4 | 21 | NO | NO |
CVE-2006-1079HIGH htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, w | Mar 9, 2006 | 7.2 | 20 | NO | NO |
CVE-2002-1562MEDIUM Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header. | May 12, 2003 | 5.0 | 20 | NO | NO |
CVE-2000-0900HIGH Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot do | Dec 19, 2000 | 7.5 | 20 | NO | NO |
CVE-2006-4248HIGH thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file. | Oct 31, 2006 | 7.2 | 18 | NO | NO |
CVE-2007-0664MEDIUM thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files. | Feb 2, 2007 | 5.0 | 16 | NO | NO |
syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file. | Nov 6, 2005 | 2.1 | 11 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
20.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Thttpd
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.25b | 3 | 7.6 | 0.4% | 0 | 0 |
| 2.23b1 | 1 | 2.1 | 0.4% | 0 | 0 |
| 2.21b | 1 | 2.1 | 0.4% | 0 | 0 |
| 2.20b | 1 | 7.5 | 8.0% | 0 | 1 |
| 2.19 | 1 | 7.5 | 2.0% | 0 | 0 |
| 2.18 | 1 | 7.5 | 2.0% | 0 | 0 |
| 2.17 | 1 | 7.5 | 2.0% | 0 | 0 |
| 2.16 | 1 | 7.5 | 2.0% | 0 | 0 |
| 2.0.7_beta_0.4 | 1 | 5.0 | 3.6% | 0 | 1 |
| 2.0.4 | 1 | 10.0 | 5.4% | 0 | 0 |
| 2.0.3 | 1 | 10.0 | 5.4% | 0 | 0 |
| 2.0.2 | 1 | 10.0 | 5.4% | 0 | 0 |
| 2.0.1 | 1 | 10.0 | 5.4% | 0 | 0 |
| 2.0 | 1 | 10.0 | 5.4% | 0 | 0 |
| 1.95 | 1 | 10.0 | 5.4% | 0 | 0 |
| 1.90a | 1 | 10.0 | 5.4% | 0 | 0 |