privoxy CVE Vulnerabilities & Metrics

Focus on privoxy vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About privoxy Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with privoxy. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total privoxy CVEs: 28
Earliest CVE date: 11 Mar 2013, 17:55 UTC
Latest CVE date: 23 Dec 2021, 20:15 UTC

Latest CVE reference: CVE-2021-44543

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical privoxy CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.86

Max CVSS: 7.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 18
7.0-8.9 10
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS privoxy CVEs

These are the five CVEs with the highest CVSS scores for privoxy, sorted by severity first and recency.

All CVEs for privoxy

CVE-2021-44543 privoxy vulnerability CVSS: 2.6 23 Dec 2021, 20:15 UTC

An XSS vulnerability was found in Privoxy which was fixed in cgi_error_no_template() by encode the template name when Privoxy is configured to servce the user-manual itself.

CVE-2021-44542 privoxy vulnerability CVSS: 5.0 23 Dec 2021, 20:15 UTC

A memory leak vulnerability was found in Privoxy when handling errors.

CVE-2021-44541 privoxy vulnerability CVSS: 5.0 23 Dec 2021, 20:15 UTC

A vulnerability was found in Privoxy which was fixed in process_encrypted_request_headers() by freeing header memory when failing to get the request destination.

CVE-2021-44540 privoxy vulnerability CVSS: 5.0 23 Dec 2021, 20:15 UTC

A vulnerability was found in Privoxy which was fixed in get_url_spec_param() by freeing memory of compiled pattern spec before bailing.

CVE-2021-20209 privoxy vulnerability CVSS: 5.0 25 May 2021, 20:15 UTC

A memory leak vulnerability was found in Privoxy before 3.0.29 in the show-status CGI handler when no action files are configured.

CVE-2021-20217 privoxy vulnerability CVSS: 7.8 25 Mar 2021, 19:15 UTC

A flaw was found in Privoxy in versions before 3.0.31. An assertion failure triggered by a crafted CGI request may lead to denial of service. The highest threat from this vulnerability is to system availability.

CVE-2021-20216 privoxy vulnerability CVSS: 7.8 25 Mar 2021, 19:15 UTC

A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.

CVE-2021-20215 privoxy vulnerability CVSS: 7.8 25 Mar 2021, 19:15 UTC

A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the show-status CGI handler when memory allocations fail can lead to a system crash.

CVE-2021-20214 privoxy vulnerability CVSS: 7.8 25 Mar 2021, 19:15 UTC

A flaw was found in Privoxy in versions before 3.0.29. Memory leaks in the client-tags CGI handler when client tags are configured and memory allocations fail can lead to a system crash.

CVE-2021-20213 privoxy vulnerability CVSS: 4.3 25 Mar 2021, 19:15 UTC

A flaw was found in Privoxy in versions before 3.0.29. Dereference of a NULL-pointer that could result in a crash if accept-intercepted-requests was enabled, Privoxy failed to get the request destination from the Host header and a memory allocation failed.

CVE-2021-20212 privoxy vulnerability CVSS: 7.8 25 Mar 2021, 19:15 UTC

A flaw was found in Privoxy in versions before 3.0.29. Memory leak if multiple filters are executed and the last one is skipped due to a pcre error leading to a system crash.

CVE-2021-20211 privoxy vulnerability CVSS: 7.8 25 Mar 2021, 19:15 UTC

A flaw was found in Privoxy in versions before 3.0.29. Memory leak when client tags are active can cause a system crash.

CVE-2021-20210 privoxy vulnerability CVSS: 7.8 25 Mar 2021, 19:15 UTC

A flaw was found in Privoxy in versions before 3.0.29. Memory leak in the show-status CGI handler when no filter files are configured can lead to a system crash.

CVE-2020-35502 privoxy vulnerability CVSS: 7.8 25 Mar 2021, 19:15 UTC

A flaw was found in Privoxy in versions before 3.0.29. Memory leaks when a response is buffered and the buffer limit is reached or Privoxy is running out of memory can lead to a system crash.

CVE-2021-20276 privoxy vulnerability CVSS: 5.0 09 Mar 2021, 14:15 UTC

A flaw was found in privoxy before 3.0.32. Invalid memory access with an invalid pattern passed to pcre_compile() may lead to denial of service.

CVE-2021-20275 privoxy vulnerability CVSS: 5.0 09 Mar 2021, 14:15 UTC

A flaw was found in privoxy before 3.0.32. A invalid read of size two may occur in chunked_body_is_complete() leading to denial of service.

CVE-2021-20274 privoxy vulnerability CVSS: 5.0 09 Mar 2021, 14:15 UTC

A flaw was found in privoxy before 3.0.32. A crash may occur due a NULL-pointer dereference when the socks server misbehaves.

CVE-2021-20273 privoxy vulnerability CVSS: 5.0 09 Mar 2021, 14:15 UTC

A flaw was found in privoxy before 3.0.32. A crash can occur via a crafted CGI request if Privoxy is toggled off.

CVE-2021-20272 privoxy vulnerability CVSS: 5.0 09 Mar 2021, 14:15 UTC

A flaw was found in privoxy before 3.0.32. An assertion failure could be triggered with a crafted CGI request leading to server crash.

CVE-2019-3699 privoxy vulnerability CVSS: 7.2 24 Jan 2020, 13:15 UTC

UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of privoxy on openSUSE Leap 15.1, Factory allows local attackers to escalate from user privoxy to root. This issue affects: openSUSE Leap 15.1 privoxy version 3.0.28-lp151.1.1 and prior versions. openSUSE Factory privoxy version 3.0.28-2.1 and prior versions.

CVE-2016-1983 privoxy vulnerability CVSS: 5.0 27 Jan 2016, 20:59 UTC

The client_host function in parsers.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via an empty HTTP Host header.

CVE-2016-1982 privoxy vulnerability CVSS: 5.0 27 Jan 2016, 20:59 UTC

The remove_chunked_transfer_coding function in filters.c in Privoxy before 3.0.24 allows remote attackers to cause a denial of service (invalid read and crash) via crafted chunk-encoded content.

CVE-2015-1031 privoxy vulnerability CVSS: 7.5 10 Feb 2015, 19:59 UTC

Multiple use-after-free vulnerabilities in Privoxy before 3.0.22 allow remote attackers to have unspecified impact via vectors related to (1) the unmap function in list.c or (2) "two additional unconfirmed use-after-free complaints made by Coverity scan." NOTE: some of these details are obtained from third party information.

CVE-2015-1382 privoxy vulnerability CVSS: 5.0 03 Feb 2015, 16:59 UTC

parsers.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (invalid read and crash) via vectors related to an HTTP time header.

CVE-2015-1381 privoxy vulnerability CVSS: 5.0 03 Feb 2015, 16:59 UTC

Multiple unspecified vulnerabilities in pcrs.c in Privoxy before 3.0.23 allow remote attackers to cause a denial of service (segmentation fault or memory consumption) via unspecified vectors.

CVE-2015-1380 privoxy vulnerability CVSS: 5.0 03 Feb 2015, 16:59 UTC

jcc.c in Privoxy before 3.0.23 allows remote attackers to cause a denial of service (abort) via a crafted chunk-encoded body.

CVE-2015-1201 privoxy vulnerability CVSS: 5.0 20 Jan 2015, 15:59 UTC

Privoxy before 3.0.22 allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

CVE-2015-1030 privoxy vulnerability CVSS: 5.0 20 Jan 2015, 15:59 UTC

Memory leak in the rfc2553_connect_to function in jbsocket.c in Privoxy before 3.0.22 allows remote attackers to cause a denial of service (memory consumption) via a large number of requests that are rejected because the socket limit is reached.

CVE-2013-2503 privoxy vulnerability CVSS: 5.8 11 Mar 2013, 17:55 UTC

Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.