CVE-2012-10053: Pmsoftware Simple Web Server

Critical severity, CVSS 9.3. EPSS: 1.7% chance of exploitation in the next 30 days.

Simple Web Server 2.2 rc2 contains a stack-based buffer overflow vulnerability in its handling of the Connection HTTP header. When a remote attacker sends an overly long string in this header, the server uses vsprintf() without proper bounds checking, leading to a buffer overflow on the stack. This flaw allows remote attackers to execute arbitrary code with the privileges of the web server process. The vulnerability is triggered before authentication.

Affected products

  • Pmsoftware Simple Web Server: version 2.2 rc2 only

Published 2025-08-08. Last modified 2026-06-16.