Products: 1
    Vulnerabilities: 3
    Known Exploited: 0
    1
    Critical Level Threats
    1
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2009-4491

    thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator.

    Last Modified: Apr 23, 2026
    Published: Jan 13, 2010

    CVE-1999-1456

    thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename.

    Last Modified: Apr 16, 2026
    Published: Dec 31, 1999

    CVE-1999-1457

    Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.

    Last Modified: Apr 16, 2026
    Published: Nov 16, 1999
    Items Per Page
    Thttpd Vulnerabilities & Security CVEs | CVE-DB