CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1
Tinyproxy - HTTP Request Smuggling via Duplicate Content-Length Headers
Tinyproxy - HTTP Request Smuggling via CL/TE Desynchronization
Tinyproxy - Stathost Detection Bypass via Host Header Manipulation
Tinyproxy HTTP request parsing desynchronization via case-sensitive Transfer-Encoding handling
tinyproxy Integer Overflow in HTTP Chunked Transfer-Encoding Parser Leading to Denial of Service
Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.c.
A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trig…
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier u…
main.c in Tinyproxy 1.8.4 and earlier creates a /run/tinyproxy/tinyproxy.pid file after dropping privileges to a non-root account, which might allow local user…
tinyproxy HTTP proxy 1.5.0, 1.4.3, and earlier allows remote attackers to execute arbitrary code via memory that is freed twice (double-free).
Buffer overflow in Tinyproxy HTTP proxy 1.3.3 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a lo…
Showing 1 to 11 CVEs · page 1