VYPR

rpm package

opensuse/wget&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/wget&distro=openSUSE%20Leap%2016.0

Vulnerabilities (6)

  • CVE-2026-16599MedAug 25, 2026
    affected < 1.25.0-160000.4.1fixed 1.25.0-160000.4.1

    GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server

  • CVE-2026-15146MedJul 10, 2026
    affected < 1.25.0-160000.3.1fixed 1.25.0-160000.3.1

    GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port

  • CVE-2026-58472MedJul 7, 2026
    affected < 1.25.0-160000.3.1fixed 1.25.0-160000.3.1

    GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters

  • CVE-2026-58471MedJul 7, 2026
    affected < 1.25.0-160000.3.1fixed 1.25.0-160000.3.1

    GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger memory corruption through a server-supplied filename requiring character set conversion. When t

  • CVE-2026-58470MedJul 7, 2026
    affected < 1.25.0-160000.3.1fixed 1.25.0-160000.3.1

    GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range h

  • CVE-2026-58469HigJul 7, 2026
    affected < 1.25.0-160000.3.1fixed 1.25.0-160000.3.1

    GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only U