CVE Tools

Jan-kneschke

1 CVEs tracked since 2015. Since Jun 2015, none of them reached CISA KEV.

Jan-kneschke CVEs per month

Jun 2015 to Jun 2015. Point at a month, or focus the strip and use the arrow keys.
Jan-kneschke CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2015-0610

Products

The products that kept showing up in Jan-kneschke's monthly top three, with their CVEs summed over those months.

  1. Lighttpd11 month

Latest CVEs

The 8 most recently published vulnerabilities affecting Jan-kneschke.

  1. BDU:2024-03964Уязвимость веб-сервера lighttpd, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю обойти механизм защиты ASLR и получить несанкционированный доступ к защищаемой информации5.3
  2. BDU:2024-03962Уязвимость веб-сервера lighttpd, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю обойти механизм защиты ASLR и получить несанкционированный доступ к защищаемой информации5.3
  3. BDU:2024-03963Уязвимость веб-сервера lighttpd, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю обойти механизм защиты ASLR и получить несанкционированный доступ к защищаемой информации5.3
  4. CVE-2022-41556A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is rel...7.5
  5. CVE-2022-37797In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the ...7.5
  6. CVE-2019-11072lighttpd before 1.4.54 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malicious H...9.8
  7. CVE-2018-19052An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mo...7.5
  8. CVE-2015-3200mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a...7.5

The record

Peak rank
#127 in Jun 2015
Busiest month shown
Jun 2015, 1 CVEs
Months with a KEV entry
0 since Jun 2015
Monthly snapshots
1 since 2015
Jan-kneschke's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store