← Back

Bozohttpd

bozohttpd

Vendor: Eterna • 3 CVEs

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Eterna
Netbsd
2Bozohttpd
Netbsd
May 6, 2026
Jul 24, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions...Show more
bozotic HTTP server (aka bozohttpd) before 20140708, as used in NetBSD, truncates paths when checking .htpasswd restrictions, which allows remote attackers to bypass the HTTP authentication scheme and access restrictions via a long path.Show less
1Eterna
1Bozohttpd
Apr 29, 2026
Aug 2, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
bozotic HTTP server (aka bozohttpd) before 20100621 allows remote attackers to list the contents of home directories, and determine the existence of user accounts, via multiple requests for URIs beginning with /~ sequenc...Show more
bozotic HTTP server (aka bozohttpd) before 20100621 allows remote attackers to list the contents of home directories, and determine the existence of user accounts, via multiple requests for URIs beginning with /~ sequences.Show less
1Eterna
1Bozohttpd
Apr 29, 2026
Aug 2, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
bozotic HTTP server (aka bozohttpd) 20090522 through 20100512 allows attackers to cause a denial of service via vectors related to a "wrong code generation interaction with GCC."