Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a long path.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15474
http://www.securityfocus.com/bid/9871
http://secunia.com/advisories/10385/