Skip to main content

Vendor/product archive

gnu / libidn2 CVEs

Beta · best-effort

4 CVEs tagged to gnu / libidn23 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2019-12290

Published Oct 22, 2019

GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-18224

Published Oct 21, 2019

idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14062

Published Aug 31, 2017

Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impa…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-14061

Published Aug 31, 2017

Integer overflow in the _isBidi function in bidi.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1