CVE-2021-20212
- EPSS 1.12%
- Published 25.03.2021 19:15:12
- Last modified 21.11.2024 05:46:08
A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash.
CVE-2021-20211
- EPSS 0.83%
- Published 25.03.2021 19:15:12
- Last modified 21.11.2024 05:46:08
A flaw was found in Privoxy in versions before 3.0.29. Memory leak when client tags are active can cause a system crash.
CVE-2021-20210
- EPSS 1.12%
- Published 25.03.2021 19:15:12
- Last modified 21.11.2024 05:46:08
A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.
CVE-2020-35502
- EPSS 0.64%
- Published 25.03.2021 19:15:12
- Last modified 21.11.2024 05:27:26
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a system crash.
CVE-2021-20276
- EPSS 2.81%
- Published 09.03.2021 14:15:13
- Last modified 21.11.2024 05:46:15
A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.
CVE-2021-20275
- EPSS 0.57%
- Published 09.03.2021 14:15:12
- Last modified 21.11.2024 05:46:15
A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.
CVE-2021-20274
- EPSS 0.7%
- Published 09.03.2021 14:15:12
- Last modified 21.11.2024 05:46:15
A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.
CVE-2021-20273
- EPSS 2.82%
- Published 09.03.2021 14:15:12
- Last modified 21.11.2024 05:46:15
A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.
CVE-2021-20272
- EPSS 2.55%
- Published 09.03.2021 14:15:12
- Last modified 21.11.2024 05:46:15
A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.
CVE-2019-3699
- EPSS 0.12%
- Published 24.01.2020 13:15:11
- Last modified 21.11.2024 04:42:21
UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and ...