CVE Tools

Acme-labs

13 CVEs tracked since 2000. Since Jul 2000, none of them reached CISA KEV.

Acme-labs CVEs per month

Jul 2000 to Feb 2007. Point at a month, or focus the strip and use the arrow keys.
Acme-labs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2000-0710
2000-08null or fewer
2000-09null or fewer
2000-10null or fewer
2000-11null or fewer
2000-12null or fewer
2001-0110
2001-02null or fewer
2001-03null or fewer
2001-04null or fewer
2001-05null or fewer
2001-06null or fewer
2001-07null or fewer
2001-08null or fewer
2001-09null or fewer
2001-10null or fewer
2001-11null or fewer
2001-12null or fewer
2002-01null or fewer
2002-02null or fewer
2002-0310
2002-04null or fewer
2002-05null or fewer
2002-06null or fewer
2002-07null or fewer
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-0430
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-09null or fewer
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-04null or fewer
2005-05null or fewer
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-09null or fewer
2005-10null or fewer
2005-1110
2005-1220
2006-01null or fewer
2006-02null or fewer
2006-0320
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-1010
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-0210

Products

The products that kept showing up in Acme-labs's monthly top three, with their CVEs summed over those months.

  1. Thttpd108 months
  2. Perlcal22 months
  3. Acme Server11 month

Latest CVEs

The 13 most recently published vulnerabilities affecting Acme-labs.

  1. CVE-2007-0664thttpd before 2.25b-r6 in Gentoo Linux is started from the system root directory (/) by the Gentoo baselayout 1.12.6 package, which allows remote attackers to read arbitrary files.5.0
  2. CVE-2006-4248thttpd on Debian GNU/Linux, and possibly other distributions, allows local users to create or touch arbitrary files via a symlink attack on the start_thttpd temporary file.7.2
  3. CVE-2006-1078Multiple buffer overflows in htpasswd, as used in Acme thttpd 2.25b, and possibly other products such as Apache, might allow local users to gain privileges via (1) a long command line argument and ...8.4
  4. CVE-2006-1079htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privileges via shell metacharacters in a command line argument, which is used in a...7.2
  5. CVE-2005-4162Cross-site scripting (XSS) vulnerability in cal_make.pl in ACME PerlCal 2.99.20 allows remote attackers to inject arbitrary web script or HTML via the p0 parameter.4.3
  6. CVE-2004-2628Multiple directory traversal vulnerabilities in thttpd 2.07 beta 0.4, when running on Windows, allow remote attackers to read arbitrary files via a URL that contains (1) a hex-encoded backslash dot...5.0
  7. CVE-2005-3124syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.2.1
  8. CVE-2002-1562Directory traversal vulnerability in thttpd, when using virtual hosting, allows remote attackers to read arbitrary files via .. (dot dot) sequences in the Host: header.5.0
  9. CVE-2002-0733Cross-site scripting vulnerability in thttpd 2.20 and earlier allows remote attackers to execute arbitrary script via a URL to a nonexistent page, which causes thttpd to insert the script into a 40...7.5
  10. CVE-2001-0748Acme.Serve 1.7, as used in Cisco Secure ACS Unix and possibly other products, allows remote attackers to read arbitrary files by prepending several / (slash) characters to the URI.5.0
  11. CVE-2001-0463Directory traversal vulnerability in cal_make.pl in PerlCal allows remote attackers to read arbitrary files via a .. (dot dot) in the p0 parameter.5.0
  12. CVE-2000-0900Directory traversal vulnerability in ssi CGI program in thttpd 2.19 and earlier allows remote attackers to read arbitrary files via a "%2e%2e" string, a variation of the .. (dot dot) attack.7.5
  13. CVE-2000-0359Buffer overflow in Trivial HTTP (THTTPd) allows remote attackers to cause a denial of service or execute arbitrary commands via a long If-Modified-Since header.10.0

The record

Peak rank
#24 in Apr 2003
Busiest month shown
Apr 2003, 3 CVEs
Months with a KEV entry
0 since Jul 2000
Monthly snapshots
9 since 2000
Acme-labs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store