Vulnerabilities > PPS Jussieu

DATE CVE VULNERABILITY TITLE RISK
2009-12-24 CVE-2009-4413 Numeric Errors vulnerability in Pps.Jussieu Polipo 0.9.12/0.9.8/1.0.4
The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and a segmentation fault.
network
low complexity
pps-jussieu CWE-189
5.0
2009-12-24 CVE-2009-3305 Improper Input Validation vulnerability in Pps.Jussieu Polipo 1.0.4
Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.
network
low complexity
pps-jussieu CWE-20
5.0
2009-09-09 CVE-2008-7191 Denial-Of-Service vulnerability in Polipo
Unspecified vulnerability in Polipo before 1.0.4 allows remote attackers to cause a denial of service (crash) via a long request URL.
network
low complexity
pps-jussieu
5.0