Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gnu wget vulnerabilities and exploits
(subscribe to this query)
516
VMScore
CVE-2021-31879
GNU Wget up to and including 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
Gnu Wget
Broadcom Brocade Fabric Operating System Firmware -
Netapp Cloud Backup -
Netapp Ontap Select Deploy Administration Utility -
Netapp A250 Firmware -
Netapp 500f Firmware -
1 Github repository
505
VMScore
CVE-2006-6719
The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote malicious users to cause a denial of service (application crash) via a malicious FTP server with a large number of blank 220 responses to the SYST command.
Gnu Wget 1.8.2
Gnu Wget 1.7
Gnu Wget 1.9
Gnu Wget 1.10
Gnu Wget 1.6
Gnu Wget 1.8
Gnu Wget 1.8.1
Gnu Wget 1.10.1
Gnu Wget 1.9.1
Gnu Wget 1.7.1
Gnu Wget 1.5.3
Gnu Wget 1.10.2
1 EDB exploit
505
VMScore
CVE-2004-1488
wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal escape sequences and execute arbitrary code.
Gnu Wget 1.8.2
Gnu Wget 1.9
Gnu Wget 1.8
Gnu Wget 1.8.1
Gnu Wget 1.9.1
1 EDB exploit
447
VMScore
CVE-2019-3823
libcurl versions from 7.34.0 to prior to 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set...
Haxx Libcurl
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 18.10
Debian Debian Linux 9.0
Netapp Clustered Data Ontap
Oracle Http Server 12.2.1.3.0
Oracle Secure Global Desktop 5.4
Oracle Communications Operations Monitor 3.4
Oracle Communications Operations Monitor 4.0
445
VMScore
CVE-2018-16890
libcurl versions from 7.36.0 to prior to 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vul...
Haxx Libcurl
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 18.10
Debian Debian Linux 9.0
Netapp Clustered Data Ontap
Siemens Sinema Remote Connect Client
Oracle Http Server 12.2.1.3.0
Oracle Secure Global Desktop 5.4
Oracle Communications Operations Monitor 3.4
Oracle Communications Operations Monitor 4.0
Redhat Enterprise Linux 8.0
F5 Big-ip Access Policy Manager
1 Github repository
445
VMScore
CVE-2004-1487
wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.
Gnu Wget 1.8.2
Gnu Wget 1.9
Gnu Wget 1.8
Gnu Wget 1.8.1
Gnu Wget 1.9.1
445
VMScore
CVE-2002-1344
Directory traversal vulnerability in wget prior to 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
Gnu Wget 1.8.2
Gnu Wget 1.7
Sun Cobalt Raq Xtr
Gnu Wget 1.6
Gnu Wget 1.8
Gnu Wget 1.8.1
Gnu Wget 1.7.1
Gnu Wget 1.5.3
445
VMScore
CVE-1999-0402
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
Gnu Wget 1.5.3
383
VMScore
CVE-2017-6508
CRLF injection vulnerability in the url_parse function in url.c in Wget up to and including 1.19.1 allows remote malicious users to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
Gnu Wget
265
VMScore
CVE-2004-2014
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
Gnu Wget 1.8.2
Gnu Wget 1.7
Gnu Wget 1.9
Gnu Wget 1.6
Gnu Wget 1.8
Gnu Wget 1.8.1
Gnu Wget 1.9.1
Gnu Wget 1.7.1
Gnu Wget 1.5.3
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
TCP
CVE-2024-4577
CVE-2024-2695
CVE-2024-31870
injection
CVE-2024-3813
arbitrary code
CVE-2024-27801
CVE-2024-30120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »