Libproxy is a proxy configuration abstraction library embedded across desktop environments and applications to manage system-level proxy settings, despite its narrow product scope carrying significance through widespread distribution in Linux and related systems. The vendor's disclosures center on memory-safety and code-generation vulnerabilities including buffer overflows, out-of-bounds writes, code injection, and uncontrolled recursion—flaws inherent to a configuration-parsing library that processes untrusted proxy input. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libproxy Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-4505HIGH Heap-based buffer overflow in the px_pac_reload function in lib/pac.c in libproxy 0.2.x and 0.3.x allows remote servers to have an unspecified impact via a crafted Content-Length s | Nov 11, 2012 | 10.0 | 32 | NO | NO |
CVE-2012-4504HIGH Stack-based buffer overflow in the url::get_pac function in url.cpp in libproxy 0.4.x before 0.4.9 allows remote servers to have an unspecified impact via a large proxy.pac file. | Nov 11, 2012 | 10.0 | 32 | NO | NO |
CVE-2020-26154CRITICAL url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header. | Sep 30, 2020 | 9.8 | 31 | NO | NO |
CVE-2020-25219HIGH url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a n | Sep 9, 2020 | 7.5 | 26 | NO | NO |
CVE-2012-5580HIGH Format string vulnerability in the print_proxies function in bin/proxy.c in libproxy 0.3.1 might allow context-dependent attackers to cause a denial of service (crash) and possibly | Oct 27, 2014 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libproxy Project.
Media articles that mention a CVE ID that affects a product developed by Libproxy Project — matched by CVE ID, not by vendor name.