CVE-2012-10053: Pmsoftware Simple Web Server
Critical severity, CVSS 9.3. EPSS: 1.7% chance of exploitation in the next 30 days.
Simple Web Server 2.2 rc2 contains a stack-based buffer overflow vulnerability in its handling of the Connection HTTP header. When a remote attacker sends an overly long string in this header, the server uses vsprintf() without proper bounds checking, leading to a buffer overflow on the stack. This flaw allows remote attackers to execute arbitrary code with the privileges of the web server process. The vulnerability is triggered before authentication.
Affected products
- Pmsoftware Simple Web Server: version 2.2 rc2 only
Published 2025-08-08. Last modified 2026-06-16.