CVE-2016-1983
- EPSS 1.82%
- Published 27.01.2016 20:59:04
- Last modified 12.04.2025 10:46:40
The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.
CVE-2016-1982
- EPSS 2.36%
- Published 27.01.2016 20:59:03
- Last modified 12.04.2025 10:46:40
The remove_chunked_transfer_coding function in filters.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via crafted chunk-encoded content.
CVE-2015-1031
- EPSS 0.66%
- Published 10.02.2015 19:59:01
- Last modified 12.04.2025 10:46:40
Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via vectors related to (1) the unmap function in list.c or (2) "two additional unconfirmed use-after-free complaints made by Coverity s...
- EPSS 2.21%
- Published 03.02.2015 16:59:13
- Last modified 12.04.2025 10:46:40
parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.
- EPSS 2.21%
- Published 03.02.2015 16:59:12
- Last modified 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory consumption) via unspecified vectors.
- EPSS 1.01%
- Published 03.02.2015 16:59:11
- Last modified 12.04.2025 10:46:40
jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.
- EPSS 0.47%
- Published 20.01.2015 15:59:10
- Last modified 12.04.2025 10:46:40
Privoxy before 3.0.22 allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
- EPSS 0.54%
- Published 20.01.2015 15:59:09
- Last modified 12.04.2025 10:46:40
Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests that are rejected because the socket limit is reached.
CVE-2013-2503
- EPSS 3.48%
- Published 11.03.2013 17:55:01
- Last modified 11.04.2025 00:51:21
Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication ...