Direct Vulnerabilities

Known vulnerabilities in the lighttpd package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2018-25103

<1.4.52-1
  • H
Memory Leak

<1.4.59-1+deb11u2
  • H
NULL Pointer Dereference

<1.4.59-1+deb11u2
  • H
Incorrect Calculation

<1.4.59-1
  • M
Out-of-bounds Write

<1.4.59-1+deb11u1
  • C
Integer Overflow or Wraparound

<1.4.53-4
  • H
Directory Traversal

<1.4.52-1
  • L
Arbitrary Code Injection

<1.4.37-1
  • L
Cryptographic Issues

<1.4.35-4
  • M
Directory Traversal

<1.4.33-1+nmu3
  • C
SQL Injection

<1.4.33-1+nmu3
  • M
Use After Free

<1.4.33-1+nmu1
  • H
Access Restriction Bypass

<1.4.33-1+nmu1
  • H
Inadequate Encryption Strength

<1.4.33-1+nmu1
  • L
Cryptographic Issues

<1.4.31-4
  • M
Resource Management Errors

<1.4.31-2
  • L
Cryptographic Issues

<1.4.30-1
  • L
CVE-2011-4362

<1.4.30-1
  • M
Improper Input Validation

<1.4.30-1
  • M
Resource Management Errors

<1.4.26-1
  • M
Cryptographic Issues

<1.4.30-1
  • L
Information Exposure

<1.4.19-5
  • L
Information Exposure

<1.4.19-5
  • M
Resource Management Errors

<1.4.19-5
  • L
CVE-2008-1531

<1.4.19-2
  • M
Information Exposure

<1.4.19-1
  • L
Information Exposure

<1.4.18-4
  • M
Resource Management Errors

<1.4.18-2
  • M
Out-of-Bounds

<1.4.18-1
  • M
CVE-2007-3946

<1.4.16-1
  • H
CVE-2007-3949

<1.4.16-1
  • M
CVE-2007-3947

<1.4.16-1
  • L
CVE-2007-3948

<1.4.16-1
  • M
CVE-2007-3950

<1.4.16-1
  • L
CVE-2007-1870

<1.4.15-1
  • M
CVE-2007-1869

<1.4.15-1