Vulnerabilities > Libproxy Project > Libproxy > 0.3.1

DATE CVE VULNERABILITY TITLE RISK
2020-09-30 CVE-2020-26154 Classic Buffer Overflow vulnerability in multiple products
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
network
low complexity
libproxy-project fedoraproject debian opensuse CWE-120
critical
9.8
2014-10-27 CVE-2012-5580 Code Injection vulnerability in Libproxy Project Libproxy 0.3.1
Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a proxy name, as demonstrated using the http_proxy environment variable or a PAC file.
network
low complexity
libproxy-project CWE-94
7.5