lighttpd before 1.4.26, and 1.5.x, allocates a buffer for each read operation that occurs for a request, which allows remote attackers to cause a denial of service (memory consumption) by breaking a request into small pieces that are sent at a slow rate.
We have discovered 797 live websites that are affected by CVE-2010-0295.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 797 live websites (1.63% of lighttpd install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 8 versions ( 14% of all versions) |
| 72 websites | |
| 516 websites | |
| 63 websites | |
| 61 websites | |
| 12 websites | |
| 8 websites | |
| 8 websites | |
| 7 websites | |
| 6 websites | |
| 6 websites |
| .fr | 483 websites |
| .com | 166 websites |
| .org | 43 websites |
| .net | 24 websites |
| .co.uk | 15 websites |
| .dk | 6 websites |
| .org.uk | 6 websites |
| .ch | 5 websites |
| .nl | 4 websites |
| .de | 4 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***.*********.com | ***,*** | ||
| ***.****.fr | ***,*** | ||
| ********.net | ***,*** | ||
| ***********.pl | ***,*** | ||
| *****.*****.net | ***,*** | ||
| ********.****.****.fr | *,***,*** | ||
| *****.net | *,***,*** | ||
| ******.nu | *,***,*** | ||
| ***.org | *,***,*** | ||
| ***.**.com | *,***,*** |