Acme-labs
13 CVEs tracked since 2000. Since Jul 2000, none of them reached CISA KEV.
Acme-labs CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2000-07 | 1 | 0 |
| 2000-08 | null or fewer | |
| 2000-09 | null or fewer | |
| 2000-10 | null or fewer | |
| 2000-11 | null or fewer | |
| 2000-12 | null or fewer | |
| 2001-01 | 1 | 0 |
| 2001-02 | null or fewer | |
| 2001-03 | null or fewer | |
| 2001-04 | null or fewer | |
| 2001-05 | null or fewer | |
| 2001-06 | null or fewer | |
| 2001-07 | null or fewer | |
| 2001-08 | null or fewer | |
| 2001-09 | null or fewer | |
| 2001-10 | null or fewer | |
| 2001-11 | null or fewer | |
| 2001-12 | null or fewer | |
| 2002-01 | null or fewer | |
| 2002-02 | null or fewer | |
| 2002-03 | 1 | 0 |
| 2002-04 | null or fewer | |
| 2002-05 | null or fewer | |
| 2002-06 | null or fewer | |
| 2002-07 | null or fewer | |
| 2002-08 | null or fewer | |
| 2002-09 | null or fewer | |
| 2002-10 | null or fewer | |
| 2002-11 | null or fewer | |
| 2002-12 | null or fewer | |
| 2003-01 | null or fewer | |
| 2003-02 | null or fewer | |
| 2003-03 | null or fewer | |
| 2003-04 | 3 | 0 |
| 2003-05 | null or fewer | |
| 2003-06 | null or fewer | |
| 2003-07 | null or fewer | |
| 2003-08 | null or fewer | |
| 2003-09 | null or fewer | |
| 2003-10 | null or fewer | |
| 2003-11 | null or fewer | |
| 2003-12 | null or fewer | |
| 2004-01 | null or fewer | |
| 2004-02 | null or fewer | |
| 2004-03 | null or fewer | |
| 2004-04 | null or fewer | |
| 2004-05 | null or fewer | |
| 2004-06 | null or fewer | |
| 2004-07 | null or fewer | |
| 2004-08 | null or fewer | |
| 2004-09 | null or fewer | |
| 2004-10 | null or fewer | |
| 2004-11 | null or fewer | |
| 2004-12 | null or fewer | |
| 2005-01 | null or fewer | |
| 2005-02 | null or fewer | |
| 2005-03 | null or fewer | |
| 2005-04 | null or fewer | |
| 2005-05 | null or fewer | |
| 2005-06 | null or fewer | |
| 2005-07 | null or fewer | |
| 2005-08 | null or fewer | |
| 2005-09 | null or fewer | |
| 2005-10 | null or fewer | |
| 2005-11 | 1 | 0 |
| 2005-12 | 2 | 0 |
| 2006-01 | null or fewer | |
| 2006-02 | null or fewer | |
| 2006-03 | 2 | 0 |
| 2006-04 | null or fewer | |
| 2006-05 | null or fewer | |
| 2006-06 | null or fewer | |
| 2006-07 | null or fewer | |
| 2006-08 | null or fewer | |
| 2006-09 | null or fewer | |
| 2006-10 | 1 | 0 |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | null or fewer | |
| 2007-02 | 1 | 0 |
Products
The products that kept showing up in Acme-labs's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 13 most recently published vulnerabilities affecting Acme-labs.
- CVE-2007-0664thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.5.0
- CVE-2006-4248thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.7.2
- CVE-2006-1078Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and ...8.4
- CVE-2006-1079htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a...7.2
- CVE-2005-4162Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter.4.3
- CVE-2004-2628Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot...5.0
- CVE-2005-3124syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.2.1
- CVE-2002-1562Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.5.0
- CVE-2002-0733Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 40...7.5
- CVE-2001-0748Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI.5.0
- CVE-2001-0463Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.5.0
- CVE-2000-0900Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.7.5
- CVE-2000-0359Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.10.0
The record
- Peak rank
- #24 in Apr 2003
- Busiest month shown
- Apr 2003, 3 CVEs
- Months with a KEV entry
- 0 since Jul 2000
- Monthly snapshots
- 9 since 2000