GNU / Wget
25 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-16599 | Denial of Service in GNU wget | MEDIUM | 5.1 | Aug 25, 2026 |
| CVE-2026-58472 | GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding | MEDIUM | 6.0 | Jul 7, 2026 |
| CVE-2026-58471 | GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c | MEDIUM | 6.0 | Jul 7, 2026 |
| CVE-2026-58470 | GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing | MEDIUM | 6.9 | Jul 7, 2026 |
| CVE-2026-58469 | GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing | HIGH | 8.7 | Jul 7, 2026 |
| CVE-2024-10524 | GNU Wget is vulnerable to an SSRF attack when accessing partially-user-controlled shorthand URLs | MEDIUM | 6.5 | Nov 19, 2024 |
| CVE-2024-38428 | wget: Misinterpretation of input may lead to improper behavior | CRITICAL | 9.1 | Jun 16, 2024 |
| CVE-2021-31879 | wget: authorization header disclosure on redirect | MEDIUM | 6.5 | Apr 29, 2021 |
| CVE-2019-5953 | wget: do_conversion() heap-based buffer overflow vulnerability | CRITICAL | 9.8 | May 17, 2019 |
| CVE-2018-20483 | wget: Information exposure in set_file_metadata function in xattr.c | HIGH | 7.8 | Dec 26, 2018 |
| CVE-2018-0494 | wget: Cookie injection allows malicious website to write arbitrary cookie entries into cookie jar | HIGH | 7.1 | May 6, 2018 |
| CVE-2017-13090 | GNU Wget: heap overflow in HTTP protocol handling | HIGH | 8.8 | Oct 27, 2017 |
| CVE-2017-13089 | GNU Wget: stack overflow in HTTP protocol handling | HIGH | 8.8 | Oct 27, 2017 |
| CVE-2017-6508 | wget: CRLF injection in the url_parse function in url.c | MEDIUM | 6.1 | Mar 7, 2017 |
| CVE-2016-7098 | wget: files rejected by access list are kept on the disk for the duration of HTTP connection | HIGH | 8.1 | Sep 26, 2016 |
| CVE-2016-4971 | wget: Lack of filename checking allows arbitrary file upload via FTP redirect | HIGH | 8.8 | Jun 30, 2016 |
| CVE-2014-4877 | wget: FTP symlink arbitrary filesystem access | HIGH | 9.3 | Oct 29, 2014 |
| CVE-2010-2252 | wget: multiple HTTP client download filename vulnerability [OCERT 2010-001] | MEDIUM | 6.8 | Jul 6, 2010 |
| CVE-2009-3490 | wget: incorrect verification of SSL certificate with NUL in name | MEDIUM | 6.8 | Sep 30, 2009 |
| CVE-2006-6719 | Wget attempts to dereference NULL pointer upon response from malicious FTP server | MEDIUM | 5.0 | Dec 23, 2006 |
| CVE-2004-2014 | security flaw | LOW | 2.6 | May 10, 2005 |
| CVE-2004-1488 | security flaw | MEDIUM | 5.0 | Feb 15, 2005 |
| CVE-2004-1487 | security flaw | MEDIUM | 5.0 | Feb 15, 2005 |
| CVE-2002-1344 | security flaw | MEDIUM | 5.0 | Dec 11, 2002 |
| CVE-1999-0402 | wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself. | MEDIUM | 5.0 | Sep 29, 1999 |
Showing 1 to 25 of 25 CVEs