Логотип exploitDog
bind:CVE-2023-49606
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-49606

Количество 6

Количество 6

ubuntu логотип

CVE-2023-49606

почти 2 года назад

A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.

CVSS3: 9.8
EPSS: Высокий
nvd логотип

CVE-2023-49606

почти 2 года назад

A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.

CVSS3: 9.8
EPSS: Высокий
debian логотип

CVE-2023-49606

почти 2 года назад

A use-after-free vulnerability exists in the HTTP Connection Headers p ...

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-w78j-vw2g-233v

почти 2 года назад

A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.

CVSS3: 9.8
EPSS: Высокий
fstec логотип

BDU:2024-03549

почти 2 года назад

Уязвимость комопнента обработки заголовков HTTP-запросов демона прокси-сервера, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2024:0119-1

больше 1 года назад

Security update for tinyproxy

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-49606

A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.

CVSS3: 9.8
78%
Высокий
почти 2 года назад
nvd логотип
CVE-2023-49606

A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.

CVSS3: 9.8
78%
Высокий
почти 2 года назад
debian логотип
CVE-2023-49606

A use-after-free vulnerability exists in the HTTP Connection Headers p ...

CVSS3: 9.8
78%
Высокий
почти 2 года назад
github логотип
GHSA-w78j-vw2g-233v

A use-after-free vulnerability exists in the HTTP Connection Headers parsing in Tinyproxy 1.11.1 and Tinyproxy 1.10.0. A specially crafted HTTP header can trigger reuse of previously freed memory, which leads to memory corruption and could lead to remote code execution. An attacker needs to make an unauthenticated HTTP request to trigger this vulnerability.

CVSS3: 9.8
78%
Высокий
почти 2 года назад
fstec логотип
BDU:2024-03549

Уязвимость комопнента обработки заголовков HTTP-запросов демона прокси-сервера, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
78%
Высокий
почти 2 года назад
suse-cvrf логотип
openSUSE-SU-2024:0119-1

Security update for tinyproxy

больше 1 года назад

Уязвимостей на страницу