Vulnerability Details CVE-2007-3950
lighttpd 1.4.15, when run on 32 bit platforms, allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors involving the use of incompatible format specifiers in certain debugging messages in the (1) mod_scgi, (2) mod_fastcgi, and (3) mod_webdav modules.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.015
EPSS Ranking 80.4%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2007-3950
-
cpe:2.3:a:lighttpd:lighttpd:1.3.11
-
cpe:2.3:a:lighttpd:lighttpd:1.3.12
-
cpe:2.3:a:lighttpd:lighttpd:1.3.13
-
cpe:2.3:a:lighttpd:lighttpd:1.3.14
-
cpe:2.3:a:lighttpd:lighttpd:1.3.15
-
cpe:2.3:a:lighttpd:lighttpd:1.3.16
-
cpe:2.3:a:lighttpd:lighttpd:1.4.1
-
cpe:2.3:a:lighttpd:lighttpd:1.4.10
-
cpe:2.3:a:lighttpd:lighttpd:1.4.11
-
cpe:2.3:a:lighttpd:lighttpd:1.4.12
-
cpe:2.3:a:lighttpd:lighttpd:1.4.13
-
cpe:2.3:a:lighttpd:lighttpd:1.4.14
-
cpe:2.3:a:lighttpd:lighttpd:1.4.15
-
cpe:2.3:a:lighttpd:lighttpd:1.4.2
-
cpe:2.3:a:lighttpd:lighttpd:1.4.3
-
cpe:2.3:a:lighttpd:lighttpd:1.4.4
-
cpe:2.3:a:lighttpd:lighttpd:1.4.5
-
cpe:2.3:a:lighttpd:lighttpd:1.4.6
-
cpe:2.3:a:lighttpd:lighttpd:1.4.7
-
cpe:2.3:a:lighttpd:lighttpd:1.4.8
-
cpe:2.3:a:lighttpd:lighttpd:1.4.9