Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2013-1427
Disclosure Date: March 21, 2013 (last updated October 05, 2023)
The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP control socket and perform unauthorized actions such as forcing the use of a different version of PHP via a symlink attack or a race condition.
0
Attacker Value
Unknown
CVE-2010-0295
Disclosure Date: February 03, 2010 (last updated October 04, 2023)
lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.
0
Attacker Value
Unknown
CVE-2008-4298
Disclosure Date: September 27, 2008 (last updated October 04, 2023)
Memory leak in the http_request_parse function in request.c in lighttpd before 1.4.20 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests with duplicate request headers.
0
Attacker Value
Unknown
CVE-2008-0983
Disclosure Date: February 26, 2008 (last updated October 04, 2023)
lighttpd 1.4.18, and possibly other versions before 1.5.0, does not properly calculate the size of a file descriptor array, which allows remote attackers to cause a denial of service (crash) via a large number of connections, which triggers an out-of-bounds access.
0