VYPR

Vendor CVEs

Privoxy

All CVEs

29 total · sorted by risk
  • CVE-2019-3699HigJan 24, 2020
    risk 0.50cvss 7.7epss 0.00

    UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE…

  • CVE-2021-44542HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A memory leak vulnerability was found in Privoxy when handling errors.

  • CVE-2021-44541HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.

  • CVE-2021-44540HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.

  • CVE-2021-20209HigMay 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured.

  • CVE-2021-20217HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20216HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20215HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.

  • CVE-2021-20214HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.

  • CVE-2021-20213HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Dereference of a NULL-pointer that could result in a crash if accept-intercepted-requests was enabled, Privoxy failed to get the request destination from the Host header and a memory allocation failed.

  • CVE-2021-20212HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash.

  • CVE-2021-20211HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leak when client tags are active can cause a system crash.

  • CVE-2021-20210HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.

  • CVE-2020-35502HigMar 25, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a system crash.

  • CVE-2021-20276HigMar 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.

  • CVE-2021-20275HigMar 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

  • CVE-2021-20274HigMar 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.

  • CVE-2021-20273HigMar 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.

  • CVE-2021-20272HigMar 9, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.

  • CVE-2016-1983HigJan 27, 2016
    risk 0.49cvss 7.5epss 0.03

    The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.

  • CVE-2016-1982HigJan 27, 2016
    risk 0.49cvss 7.5epss 0.03

    The remove_chunked_transfer_coding function in filters.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via crafted chunk-encoded content.

  • CVE-2021-44543MedDec 23, 2021
    risk 0.40cvss 6.1epss 0.01

    An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Privoxy is configured to servce the user-manual itself.

  • CVE-2013-2503Mar 11, 2013
    risk 0.03cvss —epss 0.05

    Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

  • CVE-2015-1031Feb 10, 2015
    risk 0.00cvss —epss 0.02

    Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via vectors related to (1) the unmap function in list.c or (2) "two additional unconfirmed use-after-free complaints made by Coverity scan." NOTE: some of these…

  • CVE-2015-1382Feb 3, 2015
    risk 0.00cvss —epss 0.03

    parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.

  • CVE-2015-1381Feb 3, 2015
    risk 0.00cvss —epss 0.03

    Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory consumption) via unspecified vectors.

  • CVE-2015-1380Feb 3, 2015
    risk 0.00cvss —epss 0.03

    jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.

  • CVE-2015-1201Jan 20, 2015
    risk 0.00cvss —epss 0.01

    Privoxy before 3.0.22 allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

  • CVE-2015-1030Jan 20, 2015
    risk 0.00cvss —epss 0.02

    Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests that are rejected because the socket limit is reached.