Acme Labs

    Dashboard / Vendors

    Products: 3
    Vulnerabilities: 13
    Known Exploited: 0
    1
    Critical Level Threats
    5
    High Level Threats
    6
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2007-0664

    thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.

    Last Modified: Apr 23, 2026
    Published: Feb 02, 2007

    CVE-2006-4248

    thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.

    Last Modified: Apr 23, 2026
    Published: Oct 31, 2006

    CVE-2006-1079

    htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a call to the system function. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.

    Last Modified: Apr 16, 2026
    Published: Mar 09, 2006

    CVE-2006-1078

    Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and (2) a long line in a file. NOTE: since htpasswd is normally installed as a non-setuid program, and the exploit is through command line options, perhaps this issue should not be included in CVE. However, if there are some typical or recommended configurations that use htpasswd with sudo privileges, or common products that access htpasswd remotely, then perhaps it should be included.

    Last Modified: Apr 16, 2026
    Published: Mar 09, 2006

    CVE-2005-4162

    Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter.

    Last Modified: Apr 16, 2026
    Published: Dec 11, 2005
    Items Per Page
    Acme_Labs Vulnerabilities & Security CVEs | CVE-DB