CVE-2021-44543
- EPSS 0.09%
- Published 23.12.2021 20:15:12
- Last modified 21.11.2024 06:31:11
An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Privoxy is configured to servce the user-manual itself.
CVE-2021-44542
- EPSS 0.07%
- Published 23.12.2021 20:15:12
- Last modified 21.11.2024 06:31:11
A memory leak vulnerability was found in Privoxy when handling errors.
CVE-2021-44541
- EPSS 0.2%
- Published 23.12.2021 20:15:11
- Last modified 21.11.2024 06:31:11
A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.
CVE-2021-44540
- EPSS 0.12%
- Published 23.12.2021 20:15:11
- Last modified 21.11.2024 06:31:11
A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.
CVE-2021-20209
- EPSS 1.07%
- Published 25.05.2021 20:15:07
- Last modified 21.11.2024 05:46:08
A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured.
CVE-2021-20217
- EPSS 0.45%
- Published 25.03.2021 19:15:13
- Last modified 21.11.2024 05:46:09
A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system availability.
CVE-2021-20216
- EPSS 1.65%
- Published 25.03.2021 19:15:13
- Last modified 21.11.2024 05:46:08
A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.
CVE-2021-20215
- EPSS 1.12%
- Published 25.03.2021 19:15:13
- Last modified 21.11.2024 05:46:08
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.
CVE-2021-20214
- EPSS 1.12%
- Published 25.03.2021 19:15:13
- Last modified 21.11.2024 05:46:08
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.
CVE-2021-20213
- EPSS 1.26%
- Published 25.03.2021 19:15:12
- Last modified 21.11.2024 05:46:08
A flaw was found in Privoxy in versions before 3.0.29. Dereference of a NULL-pointer that could result in a crash if accept-intercepted-requests was enabled, Privoxy failed to get the request destination from the Host header and a memory allocation f...