Thttpd is a lightweight, open-source HTTP server designed for small-scale and embedded deployments where resource constraints limit the use of larger web servers. Vulnerabilities affecting this vendor center on its core HTTP server product and reflect input-handling and protocol-processing issues typical of web service implementations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thttpd over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-1999-1457HIGH Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse | Nov 16, 1999 | 7.5 | 20 | NO | NO |
CVE-1999-1456MEDIUM thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename. | Dec 31, 1999 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thttpd.
Media articles that mention a CVE ID that affects a product developed by Thttpd — matched by CVE ID, not by vendor name.