lighttpd vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the lighttpd package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2018-25103

<1.4.52-1
  • H
Memory Leak

<1.4.59-1+deb11u2
  • H
NULL Pointer Dereference

<1.4.59-1+deb11u2
  • H
Incorrect Calculation

<1.4.59-1
  • M
Out-of-bounds Write

<1.4.59-1+deb11u1
  • C
Integer Overflow or Wraparound

<1.4.53-4
  • H
Directory Traversal

<1.4.52-1
  • L
CVE-2016-1000212

<1.4.43-1
  • L
Arbitrary Code Injection

<1.4.37-1
  • L
Cryptographic Issues

<1.4.35-4
  • C
SQL Injection

<1.4.33-1+nmu3
  • M
Directory Traversal

<1.4.33-1+nmu3
  • H
Access Restriction Bypass

<1.4.33-1+nmu1
  • M
Use After Free

<1.4.33-1+nmu1
  • H
Inadequate Encryption Strength

<1.4.33-1+nmu1
  • L
Cryptographic Issues

<1.4.31-4
  • M
Resource Management Errors

<1.4.31-2
  • L
Cryptographic Issues

<1.4.30-1
  • L
CVE-2011-4362

<1.4.30-1
  • M
Improper Input Validation

<1.4.30-1
  • M
Resource Management Errors

<1.4.26-1
  • M
Cryptographic Issues

<1.4.30-1
  • L
Information Exposure

<1.4.19-5
  • L
Information Exposure

<1.4.19-5
  • M
Resource Management Errors

<1.4.19-5
  • L
CVE-2008-1531

<1.4.19-2
  • M
Information Exposure

<1.4.19-1
  • L
Information Exposure

<1.4.18-4
  • M
Resource Management Errors

<1.4.18-2
  • M
Out-of-Bounds

<1.4.18-1
  • L
CVE-2007-3948

<1.4.16-1
  • M
CVE-2007-3947

<1.4.16-1
  • M
CVE-2007-3946

<1.4.16-1
  • M
CVE-2007-3950

<1.4.16-1
  • H
CVE-2007-3949

<1.4.16-1
  • M
CVE-2007-1869

<1.4.15-1
  • L
CVE-2007-1870

<1.4.15-1