Vendor
Smallsrv
Products
2
CVEs
3
Across products
5
Status
Private
Products
2- 3 CVEs
- 2 CVEs
Recent CVEs
3| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-28994 | Cri | 0.64 | 9.8 | 0.02 | Apr 29, 2022 | Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request. | ||
| CVE-2025-41368 | Hig | 0.53 | 8.1 | 0.01 | Mar 26, 2026 | Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured… | ||
| CVE-2025-41359 | Hig | 0.51 | 7.8 | 0.00 | Mar 26, 2026 | Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name… |
- risk 0.64cvss 9.8epss 0.02
Small HTTP Server version 3.06 suffers from a remote buffer overflow vulnerability via long GET request.
- risk 0.53cvss 8.1epss 0.01
Problem in the Small HTTP Server v3.06.36 service. An authenticated path traversal vulnerability in '/' allows remote users to bypass the intended restrictions of SecurityManager and display any file if they have the appropriate permissions outside the document root configured…
- risk 0.51cvss 7.8epss 0.00
Vulnerability related to an unquoted service path in Small HTTP Server 3.06.36, specifically affecting the executable located at 'C:\Program Files (x86)\shttps_mg\http.exe service'. This misconfiguration allows a local attacker to place a malicious executable with the same name…