VYPR

Simple Web Server

by Peter Sandvik

CVEs (2)

  • CVE-2012-10053CriAug 8, 2025
    risk 0.70cvss epss 0.76

    Simple Web Server 2.2 rc2 contains a stack-based buffer overflow vulnerability in its handling of the Connection HTTP header. When a remote attacker sends an overly long string in this header, the server uses vsprintf() without proper bounds checking, leading to a buffer…

  • CVE-2002-1238Nov 12, 2002
    risk 0.03cvss epss 0.05

    Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via an HTTP request with a sequence of multiple / (slash) characters such as http://www.example.com///file/.