CVEs (25)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianGnome+2 more9Ansible Tower Debian LinuxEnterprise Linux Desktop+6 moreNov 21, 2024 Jul 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. |
2Gnome Webkitgtk2Libsoup WebkitgtkNov 21, 2024 Jun 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy sett...Show more |
3Debian GnomeRedhat8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreNov 21, 2024 Apr 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HT...Show more |
libsoup 2.32.2 and earlier does not validate certificates or clear the trust flag when the ssl-ca-file does not exist, which allows remote attackers to bypass authentication by connecting with a SSL connection. |
Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI. |