Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2021-38614
Disclosure Date: August 12, 2021 (last updated February 23, 2025)
Polipo through 1.1.1, when NDEBUG is used, allows a heap-based buffer overflow during parsing of a Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2020-36420
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
Polipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a malformed Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2011-3596
Disclosure Date: November 26, 2019 (last updated November 27, 2024)
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
0
Attacker Value
Unknown
CVE-2009-4413
Disclosure Date: December 24, 2009 (last updated October 04, 2023)
The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and a segmentation fault.
0
Attacker Value
Unknown
CVE-2009-3305
Disclosure Date: December 24, 2009 (last updated October 04, 2023)
Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-7191
Disclosure Date: September 09, 2009 (last updated October 04, 2023)
Unspecified vulnerability in Polipo before 1.0.4 allows remote attackers to cause a denial of service (crash) via a long request URL.
0
Attacker Value
Unknown
CVE-2007-4626
Disclosure Date: August 31, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Polipo before 1.0.2 allows remote attackers to cause a denial of service (daemon crash) via certain network traffic associated with entities larger than 2 Gb.
0
Attacker Value
Unknown
CVE-2007-4625
Disclosure Date: August 31, 2007 (last updated October 04, 2023)
Polipo before 1.0.2 allows remote HTTP servers to cause a denial of service (daemon crash) by aborting the response to a POST request.
0
Attacker Value
Unknown
CVE-2005-3163
Disclosure Date: October 06, 2005 (last updated February 22, 2025)
Unspecified vulnerability in Polipo 0.9.8 and earlier allows attackers to read files outside of the web root.
0