Vulnerabilities
22 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-44541 | A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination. NVD description · AI analysis pending | 7.5 group max | 1% |
| — | ||
| CVE-2021-20209 | A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured. A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2021-20210 | A flaw was found in Privoxy in versions before 3.0.29. A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2021-20272 | A flaw was found in privoxy before 3.0.32. A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash. NVD description · AI analysis pending | 7.5 | 2% |
| — | ||
| CVE-2019-3699 | UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user pri UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE Factory privoxy version 3.0.28-2.1 and prior versions. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2016-1983 +1 in the same advisory: …1982 | The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP H The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header. NVD description · AI analysis pending | 7.5 | 3% |
| — |