Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2019-17266

Disclosure Date: October 06, 2019 (last updated November 08, 2023)
libsoup from versions 2.65.1 until 2.68.1 have a heap-based buffer over-read because soup_ntlm_parse_challenge() in soup-auth-ntlm.c does not properly check an NTLM message's length before proceeding with a memcpy.
Attacker Value
Unknown

CVE-2018-12910

Disclosure Date: July 05, 2018 (last updated November 08, 2023)
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.
0
Attacker Value
Unknown

CVE-2018-11713

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a WebSocket connection.
0
Attacker Value
Unknown

CVE-2017-2885

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability.
Attacker Value
Unknown

CVE-2012-2132

Disclosure Date: August 20, 2012 (last updated October 04, 2023)
libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection.
0
Attacker Value
Unknown

CVE-2011-2524

Disclosure Date: August 31, 2011 (last updated October 04, 2023)
Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.
0
Attacker Value
Unknown

CVE-2009-0585

Disclosure Date: March 14, 2009 (last updated October 04, 2023)
Integer overflow in the soup_base64_encode function in soup-misc.c in libsoup 2.x.x before 2.2.x, and 2.x before 2.24, allows context-dependent attackers to execute arbitrary code via a long string that is converted to a base64 representation.
0
Attacker Value
Unknown

CVE-2006-5876

Disclosure Date: January 16, 2007 (last updated October 04, 2023)
The soup_headers_parse function in soup-headers.c for libsoup HTTP library before 2.2.99 allows remote attackers to cause a denial of service (crash) via malformed HTTP headers, probably involving missing fields or values.
0