Privoxy
Products
1- 29 CVEs
Recent CVEs
29| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-3699 | Hig | 0.50 | 7.7 | 0.00 | Jan 24, 2020 | UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE… | ||
| CVE-2021-44542 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2021 | A memory leak vulnerability was found in Privoxy when handling errors. | ||
| CVE-2021-44541 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2021 | A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination. | ||
| CVE-2021-44540 | Hig | 0.49 | 7.5 | 0.01 | Dec 23, 2021 | A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing. | ||
| CVE-2021-20209 | Hig | 0.49 | 7.5 | 0.02 | May 25, 2021 | A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured. | ||
| CVE-2021-20217 | Hig | 0.49 | 7.5 | 0.01 | Mar 25, 2021 | A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system availability. | ||
| CVE-2021-20216 | Hig | 0.49 | 7.5 | 0.02 | Mar 25, 2021 | A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability. | ||
| CVE-2021-20215 | Hig | 0.49 | 7.5 | 0.02 | Mar 25, 2021 | A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash. | ||
| CVE-2021-20214 | Hig | 0.49 | 7.5 | 0.02 | Mar 25, 2021 | A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash. | ||
| CVE-2021-20213 | Hig | 0.49 | 7.5 | 0.02 | Mar 25, 2021 | A flaw was found in Privoxy in versions before 3.0.29. Dereference of a NULL-pointer that could result in a crash if accept-intercepted-requests was enabled, Privoxy failed to get the request destination from the Host header and a memory allocation failed. | ||
| CVE-2021-20212 | Hig | 0.49 | 7.5 | 0.02 | Mar 25, 2021 | A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash. | ||
| CVE-2021-20211 | Hig | 0.49 | 7.5 | 0.02 | Mar 25, 2021 | A flaw was found in Privoxy in versions before 3.0.29. Memory leak when client tags are active can cause a system crash. | ||
| CVE-2021-20210 | Hig | 0.49 | 7.5 | 0.02 | Mar 25, 2021 | A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash. | ||
| CVE-2020-35502 | Hig | 0.49 | 7.5 | 0.02 | Mar 25, 2021 | A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a system crash. | ||
| CVE-2021-20276 | Hig | 0.49 | 7.5 | 0.02 | Mar 9, 2021 | A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service. | ||
| CVE-2021-20275 | Hig | 0.49 | 7.5 | 0.02 | Mar 9, 2021 | A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service. | ||
| CVE-2021-20274 | Hig | 0.49 | 7.5 | 0.02 | Mar 9, 2021 | A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves. | ||
| CVE-2021-20273 | Hig | 0.49 | 7.5 | 0.02 | Mar 9, 2021 | A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off. | ||
| CVE-2021-20272 | Hig | 0.49 | 7.5 | 0.02 | Mar 9, 2021 | A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash. | ||
| CVE-2016-1983 | Hig | 0.49 | 7.5 | 0.03 | Jan 27, 2016 | The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header. |
- risk 0.50cvss 7.7epss 0.00
UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE…
- risk 0.49cvss 7.5epss 0.01
A memory leak vulnerability was found in Privoxy when handling errors.
- risk 0.49cvss 7.5epss 0.01
A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.
- risk 0.49cvss 7.5epss 0.01
A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.
- risk 0.49cvss 7.5epss 0.02
A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured.
- risk 0.49cvss 7.5epss 0.01
A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system availability.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in Privoxy in versions before 3.0.29. Dereference of a NULL-pointer that could result in a crash if accept-intercepted-requests was enabled, Privoxy failed to get the request destination from the Host header and a memory allocation failed.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in Privoxy in versions before 3.0.29. Memory leak when client tags are active can cause a system crash.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a system crash.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.
- risk 0.49cvss 7.5epss 0.02
A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.
- risk 0.49cvss 7.5epss 0.03
The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.