← Back

Wget

wget

Vendor: Gnu • 24 CVEs

CVEs (24)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gnu
1Wget
Apr 16, 2026
Apr 27, 2005
N/A· v4
N/A· v3
5.0 MEDIUM· v2
wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for "....Show more
wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.Show less
1Gnu
1Wget
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
2.6 LOW· v2
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
2Gnu
Sun
2Cobalt Raq Xtr
Wget
Apr 16, 2026
Dec 18, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
1Gnu
1Wget
Apr 16, 2026
Jan 2, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.