ZeroHour

Vulnerabilities

11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-44928
+1 in the same advisory: …44927
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.

NVD description · AI analysis pending
5.3<1%
  • uriparser project uriparser
CVE-2026-42371
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.

NVD description · AI analysis pending
5.1<1%
  • uriparser project uriparser
CVE-2024-34402
+1 in the same advisory: …34403
An issue was discovered in uriparser through 0.9.7.

An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.

NVD description · AI analysis pending
8.6
group max
1%
  • uriparser project uriparser
  • uriparser project fedora
CVE-2021-46141
+1 in the same advisory: …46142
An issue was discovered in uriparser before 0.9.6.

An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

NVD description · AI analysis pending
5.51% PoC ×2
  • uriparser project uriparser
  • uriparser project extra packages for enterprise linux
  • uriparser project fedora
  • +1 more
CVE-2018-20721
URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing a

URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.

NVD description · AI analysis pending
9.82%
  • uriparser project uriparser
  • uriparser project debian linux
CVE-2018-19198
+2 in the same advisory: …19199 …19200
An issue was discovered in uriparser before 0.9.0.

An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.

NVD description · AI analysis pending
9.8
group max
2%
  • uriparser project uriparser
  • uriparser project debian linux