← Back

3proxy

Vendor: 3proxy • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
13proxy
13proxy
Jun 17, 2026
Aug 1, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface.
13proxy
13proxy
Apr 23, 2026
Oct 29, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Double free vulnerability in the ftpprchild function in ftppr in 3proxy 0.5 through 0.5.3i allows remote attackers to cause a denial of service (daemon crash) via multiple OPEN commands to the FTP proxy.
13proxy
13proxy
Apr 23, 2026
Apr 16, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary code via crafted transparent requests.
13proxy
13proxy
Apr 23, 2026
Feb 8, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available, whic...Show more
3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available, which makes it easier for attackers to steal credentials.Show less
13proxy
13proxy
Apr 23, 2026
Feb 8, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
3proxy 0.5 to 0.5.2, when NT-encoded passwords are being used, allows remote attackers to cause a denial of service (blocked account) via unspecified vectors related to NTLM authentication, which causes a password hash t...Show more
3proxy 0.5 to 0.5.2, when NT-encoded passwords are being used, allows remote attackers to cause a denial of service (blocked account) via unspecified vectors related to NTLM authentication, which causes a password hash to be overwritten.Show less