Search CVE reports
1 – 10 of 28 results
CVE-2021-44543
Medium prioritySome fixes available 2 of 6
An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Privoxy is configured to servce the user-manual itself.
1 affected packages
privoxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
privoxy | Not affected | Not affected | Fixed | Fixed | Vulnerable |
CVE-2021-44542
Medium priorityA memory leak vulnerability was found in Privoxy when handling errors.
1 affected packages
privoxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
privoxy | — | Not affected | Not affected | Not affected | Not affected |
CVE-2021-44541
Medium priorityA vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.
1 affected packages
privoxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
privoxy | — | Not affected | Not affected | Not affected | Not affected |
CVE-2021-44540
Medium prioritySome fixes available 2 of 6
A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.
1 affected packages
privoxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
privoxy | Not affected | Not affected | Fixed | Fixed | Needs evaluation |
CVE-2021-20276
Medium prioritySome fixes available 5 of 7
A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.
1 affected packages
privoxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
privoxy | — | Not affected | Fixed | Fixed | Fixed |
CVE-2021-20275
Medium prioritySome fixes available 5 of 7
A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.
1 affected packages
privoxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
privoxy | — | Not affected | Fixed | Fixed | Fixed |
CVE-2021-20274
Medium priorityA flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.
1 affected packages
privoxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
privoxy | — | — | Not affected | Not affected | Not affected |
CVE-2021-20273
Medium prioritySome fixes available 5 of 7
A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.
1 affected packages
privoxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
privoxy | — | Not affected | Fixed | Fixed | Fixed |
CVE-2021-20272
Medium prioritySome fixes available 5 of 7
A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.
1 affected packages
privoxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
privoxy | — | Not affected | Fixed | Fixed | Fixed |
CVE-2021-20217
Low prioritySome fixes available 5 of 7
A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system availability.
1 affected packages
privoxy
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
privoxy | — | Not affected | Fixed | Fixed | Fixed |