Show filters
29 Total Results
Displaying 1-10 of 29
Sort by:
Attacker Value
Unknown

CVE-2021-44543

Disclosure Date: December 23, 2021 (last updated February 23, 2025)
An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Privoxy is configured to servce the user-manual itself.
Attacker Value
Unknown

CVE-2021-44542

Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A memory leak vulnerability was found in Privoxy when handling errors.
Attacker Value
Unknown

CVE-2021-44541

Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.
Attacker Value
Unknown

CVE-2021-44540

Disclosure Date: December 23, 2021 (last updated February 23, 2025)
A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.
Attacker Value
Unknown

CVE-2021-20209

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured.
Attacker Value
Unknown

CVE-2020-35502

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a system crash.
Attacker Value
Unknown

CVE-2021-20214

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.
Attacker Value
Unknown

CVE-2021-20213

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A flaw was found in Privoxy in versions before 3.0.29. Dereference of a NULL-pointer that could result in a crash if accept-intercepted-requests was enabled, Privoxy failed to get the request destination from the Host header and a memory allocation failed.
Attacker Value
Unknown

CVE-2021-20212

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash.
Attacker Value
Unknown

CVE-2021-20215

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.