← Back

Pico Server

pico_server

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Pico Server
pico_server

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pico Server
1Pico Server
Apr 16, 2026
Jun 16, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each .. (dot dot) sequence in the URL, which...Show more
Directory traversal vulnerability in Pico Server (pServ) 3.3 allows remote attackers to read arbitrary files and execute arbitrary commands via a /./ (slash dot slash) before each .. (dot dot) sequence in the URL, which results in an incorrect directory depth count.Show less
1Pico Server
1Pico Server
Apr 16, 2026
Jun 11, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the CGI extension for Pico Server (pServ) 3.3 allows remote attackers to execute arbitrary code via a long HTTP request.
1Pico Server
1Pico Server
Apr 16, 2026
May 16, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Pico Server (pServ) 3.2 and earlier allows local users to read arbitrary files as the pServ user via a symlink to a file outside of the web document root.
1Pico Server
1Pico Server
Apr 16, 2026
May 16, 2005
N/A· v4
N/A· v3
7.5 HIGH· v2
Pico Server (pServ) 3.2 and earlier allows remote attackers to obtain the source code for CGI scripts via "dirname/../cgi-bin" in a URL.
1Pico Server
1Pico Server
Apr 16, 2026
May 16, 2005
N/A· v4
N/A· v3
10.0 HIGH· v2
Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences.
1Pico Server
1Pico Server
Apr 16, 2026
Dec 31, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a 1024-byte TCP stream message, which triggers an...Show more
Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a 1024-byte TCP stream message, which triggers an off-by-one buffer overflow, or (2) a long method name in an HTTP request, (3) a long version number in an HTTP request, (4) a long User-Agent header, or (5) a long file path.Show less