Search CVE reports


Toggle filters

21 – 30 of 38 results


CVE-2011-4362

Medium priority

Some fixes available 4 of 5

Integer signedness error in the base64_decode function in the HTTP authentication functionality (http_auth.c) in lighttpd 1.4 before 1.4.30 and 1.5 before SVN revision 2806 allows remote attackers to cause a denial of service...

1 affected package

lighttpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd
Show less packages

CVE-2011-3389

Low priority

Some fixes available 11 of 21

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained...

9 affected packages

gnutls26, icedtea-web, lighttpd, openjdk-6, openjdk-6b18...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
gnutls26
icedtea-web
lighttpd
openjdk-6
openjdk-6b18
openjdk-7
openssl
sun-java5
sun-java6
Show all 9 packages Show less packages

CVE-2010-0295

Medium priority
Ignored

lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that...

1 affected package

lighttpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd
Show less packages

CVE-2008-4360

Low priority

Some fixes available 1 of 4

mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is used, performs case-sensitive comparisons on filename components in configuration options, which might allow remote attackers to...

1 affected package

lighttpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd
Show less packages

CVE-2008-4359

Low priority
Ignored

lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite configuration settings before performing URL decoding, which might allow remote attackers to bypass intended access restrictions, and...

1 affected package

lighttpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd
Show less packages

CVE-2008-4298

Low priority

Some fixes available 1 of 5

Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.

1 affected package

lighttpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd
Show less packages

CVE-2008-1531

Medium priority

Some fixes available 7 of 8

The connection_state_machine function (connections.c) in lighttpd 1.4.19 and earlier, and 1.5.x before 1.5.0, allows remote attackers to cause a denial of service (active SSL connection loss) by triggering an SSL error, such as...

1 affected package

lighttpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd
Show less packages

CVE-2008-1270

Low priority
Fixed

mod_userdir in lighttpd 1.4.18 and earlier, when userdir.path is not set, uses a default of $HOME, which might allow remote attackers to read arbitrary files, as demonstrated by accessing the ~nobody directory.

1 affected package

lighttpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd
Show less packages

CVE-2008-1111

Low priority
Fixed

mod_cgi in lighttpd 1.4.18 sends the source code of CGI scripts instead of a 500 error when a fork failure occurs, which might allow remote attackers to obtain sensitive information.

1 affected package

lighttpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd
Show less packages

CVE-2008-0983

Low priority
Fixed

lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections,...

1 affected package

lighttpd

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lighttpd
Show less packages