Libevent / Libevent
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-63385 | Libevent: HTTP header handling bugs create risk of access control bypass. | CRITICAL | 9.2 | Aug 20, 2026 |
| CVE-2026-63379 | Libevent: HTTP Header smuggling | MEDIUM | 6.3 | Aug 20, 2026 |
| CVE-2026-63387 | Libevent: Off-by-one stack buffer overflow in dnsname_to_labels via crafted DNS server response | HIGH | 8.6 | Aug 20, 2026 |
| CVE-2026-63384 | Libevent: `evtag_unmarshal_header()` decodes a wire `uint32` length into a signed `int` return value. | HIGH | 8.7 | Aug 20, 2026 |
| CVE-2026-63380 | Libevent: Null Pointer Dereference in `evws_new_session` | MEDIUM | 5.7 | Aug 20, 2026 |
| CVE-2026-63382 | libevent evhttp: Multiple HTTP Parser Bugs Enable Request Smuggling | CRITICAL | 9.2 | Aug 20, 2026 |
| CVE-2026-63381 | Libevent: Dangling Pointer in `evbuffer_add_buffer_reference` | MEDIUM | 5.8 | Aug 20, 2026 |
| CVE-2026-63495 | Libevent: Unbounded memory accumulation in WebSocket server via fragmented frames | HIGH | 7.5 | Aug 20, 2026 |
| CVE-2026-63383 | Libevent: decode_tag_internal() can lead to out-of-bounds read | HIGH | 8.7 | Aug 20, 2026 |
| CVE-2026-63388 | Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX accept | HIGH | 8.4 | Aug 20, 2026 |
| CVE-2016-10197 | libevent: Out-of-bounds read in search_make_new() | HIGH | 7.5 | Mar 15, 2017 |
| CVE-2016-10196 | libevent: Stack-buffer overflow in evutil_parse_sockaddr_port() | HIGH | 7.5 | Mar 15, 2017 |
| CVE-2016-10195 | libevent: Stack-buffer overflow in the name_parse() function | CRITICAL | 9.8 | Mar 15, 2017 |
| CVE-2015-6525 | libevent: multiple integer overflows in the evbuffer APIs | HIGH | 7.5 | Aug 24, 2015 |
| CVE-2014-6272 | libevent: potential heap overflow in buffer/bufferevent APIs | HIGH | 7.5 | Aug 24, 2015 |
Showing 1 to 15 of 15 CVEs