Vulnerabilities
Vulnerable Software
Lighttpd:  >> Lighttpd  >> 1.1.1  Security Vulnerabilities
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.
CVSS Score
5.0
EPSS Score
0.056
Published
2010-02-03
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.
CVSS Score
5.0
EPSS Score
0.029
Published
2008-09-27
response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbitrary source code via requests that contain trailing (1) "." (dot) and (2) space characters, which are ignored by Windows, as demonstrated by PHP files.
CVSS Score
5.0
EPSS Score
0.007
Published
2006-03-06
LightTPD 1.4.8 and earlier, when the web root is on a case-insensitive filesystem, allows remote attackers to bypass URL checks and obtain sensitive information via file extensions with unexpected capitalization, as demonstrated by a request for index.PHP when the configuration invokes the PHP interpreter only for ".php" names.
CVSS Score
2.6
EPSS Score
0.003
Published
2006-02-18


Contact Us

Shodan ® - All rights reserved