Security readout for executives and security teams
Worm HTTP Server, a small web server product from 2000, could be crashed by a remote attacker who sent a request with an unusually long URL. The result is a denial of service: the web server stops responding until it is restarted. No data theft or system takeover is described in the public sources for this issue. Very limited in 2026. Worm HTTP Server was a niche, legacy Windows HTTP daemon; production deployments are unlikely. Any residual exposure would be an internet-reachable or intranet instance still running the unmaintained 2000-era binary. No affected vendor, product, or version list is provided in the source bundle. Low priority. This is a 25-year-old denial-of-service flaw in a niche web server that is highly unlikely to be in production. Handle through normal legacy-software retirement rather than emergency patching, but confirm no forgotten instance is internet-exposed. Mitigation focus: Inventory web servers for any Worm HTTP Server instances and retire or replace with a supported HTTP daemon.; If retirement is not immediate, restrict network exposure via firewall or reverse proxy that enforces URL length limits.; Consult vendor or original distribution channel for any late-stage patches before relying on a workaround..
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2000-0732 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- wormhttp-filename-dos(5149)CVE reference · vdb-entry, x_refsource_XF
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
