Pacparser Project maintains a niche proxy auto-config parser library that processes PAC files to determine proxy routing, with its vulnerability exposure centered on memory-safety and input-handling issues including buffer overflows, injection flaws, and out-of-bounds memory operations. The product's role in parsing untrusted configuration data creates inherent risk around input validation and buffer management. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pacparser Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25078HIGH A vulnerability classified as problematic was found in pacparser up to 1.3.x. Affected by this vulnerability is the function pacparser_find_proxy of the file src/pacparser.c. The m | Dec 13, 2022 | 7.8 | 26 | NO | NO |
CVE-2023-37360MEDIUM pacparser_find_proxy in Pacparser before 1.4.2 allows JavaScript injection, and possibly privilege escalation, when the attacker controls the URL (which may be realistic within ent | Jun 30, 2023 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pacparser Project.
Media articles that mention a CVE ID that affects a product developed by Pacparser Project — matched by CVE ID, not by vendor name.