Skip to main content

Vendor archive

pocoproject CVEs

Beta · best-effort

5 CVEs tagged to vendor pocoproject1 Critical, 1 High, 2 Medium, 1 Low, 0 Unrated.

CVE-2025-45766

Published Aug 6, 2025

poco v1.14.1-release was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by t…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-6375

Published Jun 21, 2025

A vulnerability was found in poco up to 1.14.1. It has been rated as problematic. Affected by this issue is the function MultipartInputStream of the file Net/src/MultipartReader.c…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-52389

Published Jan 27, 2024

UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer overflow because Poco::UTF32Encoding::convert() and Poco::UTF32::queryConvert() may…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-1000472

Published Jan 3, 2018

The ZipCommon::isValidPath() function in Zip/src/ZipCommon.cpp in POCO C++ Libraries before 1.8 does not properly restrict the filename value in the ZIP header, which allows attac…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0350

Published Apr 26, 2014

The Poco::Net::X509Certificate::verify method in the NetSSL library in POCO C++ Libraries before 1.4.6p4 allows man-in-the-middle attackers to spoof SSL servers via crafted DNS PT…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1