lighttpd vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the lighttpd package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2018-25103

<1.4.52-1
  • L
CVE-2024-3708

<1.4.52-1
  • H
NULL Pointer Dereference

<1.4.53-4+deb10u3
  • M
Out-of-bounds Write

<1.4.53-4+deb10u2
  • C
Integer Overflow or Wraparound

<1.4.53-4
  • H
Directory Traversal

<1.4.52-1
  • L
CVE-2016-1000212

<1.4.43-1
  • L
Arbitrary Code Injection

<1.4.37-1
  • L
Cryptographic Issues

<1.4.35-4
  • M
Directory Traversal

<1.4.33-1+nmu3
  • C
SQL Injection

<1.4.33-1+nmu3
  • M
Use After Free

<1.4.33-1+nmu1
  • H
Access Restriction Bypass

<1.4.33-1+nmu1
  • H
Inadequate Encryption Strength

<1.4.33-1+nmu1
  • L
Cryptographic Issues

<1.4.31-4
  • M
Resource Management Errors

<1.4.31-2
  • L
Cryptographic Issues

<1.4.30-1
  • L
CVE-2011-4362

<1.4.30-1
  • M
Improper Input Validation

<1.4.30-1
  • M
Resource Management Errors

<1.4.26-1
  • M
Cryptographic Issues

<1.4.30-1
  • L
Information Exposure

<1.4.19-5
  • L
Information Exposure

<1.4.19-5
  • M
Resource Management Errors

<1.4.19-5
  • L
CVE-2008-1531

<1.4.19-2
  • M
Information Exposure

<1.4.19-1
  • L
Information Exposure

<1.4.18-4
  • M
Resource Management Errors

<1.4.18-2
  • M
Out-of-Bounds

<1.4.18-1
  • L
CVE-2007-3948

<1.4.16-1
  • H
CVE-2007-3949

<1.4.16-1
  • M
CVE-2007-3950

<1.4.16-1
  • M
CVE-2007-3946

<1.4.16-1
  • M
CVE-2007-3947

<1.4.16-1
  • M
CVE-2007-1869

<1.4.15-1
  • L
CVE-2007-1870

<1.4.15-1