Pico Server is a narrowly scoped embedded or lightweight server product characterized by a modest vulnerability footprint concentrated in memory-safety and bounds-checking issues. The vendor's disclosures frequently acquire public exploit tooling, which reflects the appeal of server components to security researchers and the accessibility of memory-corruption flaws for proof-of-concept development. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pico Server over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1365HIGH Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences. | May 16, 2005 | 10.0 | 40 | NO | YES |
CVE-2002-2295HIGH Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a 1024-byt | Dec 31, 2002 | 7.5 | 37 | NO | YES |
CVE-2005-1366HIGH Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL. | May 16, 2005 | 7.5 | 31 | NO | YES |
CVE-2005-1952HIGH Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each | Jun 16, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-1953HIGH Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request. | Jun 11, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-1626HIGH Multiple buffer overflows in handlers.c for Pico Server (pServ) before 3.3 may allow attackers to execute arbitrary code. | May 17, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-1367HIGH Pico Server (pServ) 3.2 and earlier allows local users to read arbitrary files as the pServ user via a symlink to a file outside of the web document root. | May 16, 2005 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pico Server.
Media articles that mention a CVE ID that affects a product developed by Pico Server — matched by CVE ID, not by vendor name.