Vulnerabilities > GNU > Wget > Critical

DATE CVE VULNERABILITY TITLE RISK
2017-10-27 CVE-2017-13089 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects.
network
gnu debian CWE-119
critical
9.3
2017-10-27 CVE-2017-13090 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The retr.c:fd_read_body() function is called when processing OK responses.
network
gnu debian CWE-119
critical
9.3
2014-10-29 CVE-2014-4877 Path Traversal vulnerability in GNU Wget
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.
network
gnu CWE-22
critical
9.3