NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 62887 | CVE-2006-4248 | thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file. | 2 | 7.2 | High | 2016-12-20 | 2008-09-05 | View | |
| 76106 | CVE-1999-1456 | thttpd HTTP server 2.03 and earlier allows remote attackers to read arbitrary files via a GET request with more than one leading / (slash) character in the filename. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 52886 | CVE-2007-0664 | thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 51613 | CVE-2009-4491 | thttpd 2.25b0 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window"s title, or possibly execute arbitrary commands or overwrite files, via an HTTP request containing an escape sequence for a terminal emulator. | 2 | 5 | Medium | 2017-01-07 | 2010-01-14 | View | |
| 21981 | CVE-2016-7966 | Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail"s plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content. | 2 | 7.5 | High | 2017-01-19 | 2016-12-27 | View |
Page 2523 of 17672, showing 5 records out of 88360 total, starting on record 12611, ending on 12615