Skip to main content

Vendor/product archive

gnu / wget CVEs

Beta · best-effort

23 CVEs tagged to gnu / wget3 Critical, 6 High, 13 Medium, 1 Low, 0 Unrated.

CVE-2026-58472

Published Jul 7, 2026

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-58471

Published Jul 7, 2026

GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to tr…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-58470

Published Jul 7, 2026

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-58469

Published Jul 7, 2026

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malici…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-38428

Published Jun 16, 2024

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5953

Published May 17, 2019

Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspecified vectors.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-20483

Published Dec 26, 2018

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file,…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2017-13090

Published Oct 27, 2017

The retr.c:fd_read_body() function is called when processing OK responses. When the response is sent chunked in wget before 1.19.2, the chunk parser uses strtol() to read each chu…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-13089

Published Oct 27, 2017

The http.c:skip_short_body() function is called in some circumstances, such as when processing redirects. When the response is sent chunked in wget before 1.19.2, the chunk parser…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-6508

Published Mar 7, 2017

CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subc…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-7098

Published Sep 26, 2016

Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2014-4877

Published Oct 29, 2014

Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2010-2252

Published Jul 6, 2010

GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3490

Published Sep 30, 2009

GNU Wget before 1.12 does not properly handle a '\0' character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6719

Published Dec 23, 2006

The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause a denial of service (application crash) via a malicious FTP…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1487

Published Apr 27, 2005

wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious serve…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1488

Published Apr 27, 2005

wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which may allow remote malicious web servers to inject terminal es…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2014

Published Dec 31, 2004

Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2002-1344

Published Dec 18, 2002

Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0402

Published Jan 2, 1999

wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.

CVSS 5.0 · Medium
Buzz score
6.0
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1