Webfs is a lightweight web server software with a narrow but prominent footprint in embedded and constrained environments. The recorded vulnerabilities center on its core web-serving functionality, with observed issues spanning information-disclosure pathways and logic flaws characteristic of minimal HTTP implementations. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webfs over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0833HIGH Stack-based buffer overflow in webfs before 1.20 allows attackers to execute arbitrary code by creating directories that result in a long pathname. | Nov 17, 2003 | 7.5 | 30 | NO | YES |
CVE-2003-0445HIGH Buffer overflow in webfs before 1.17.1 allows remote attackers to execute arbitrary code via an HTTP request with a long Request-URI. | Jul 24, 2003 | 7.5 | 25 | NO | NO |
CVE-2013-0347HIGH The Gentoo init script for webfs uses world-readable permissions for /var/log/webfsd.log, which allows local users to have unspecified impact by reading the file. | Nov 16, 2014 | 7.2 | 23 | NO | NO |
CVE-2003-0832MEDIUM Directory traversal vulnerability in webfs before 1.20 allows remote attackers to read arbitrary files via .. (dot dot) sequences in a Hostname header. | Nov 17, 2003 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webfs.
Media articles that mention a CVE ID that affects a product developed by Webfs — matched by CVE ID, not by vendor name.