Aggregates CVE and security vulnerability intelligence across all 3proxy-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk memory corruption, vendor risk buffer overflow, and vendor risk denial of service and related problems; some flaws may lead to vendor impact memory corruption.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2019-14495 | webadmin.c in 3proxy before 0.8.13 has an out-of-bounds write in the admin interface. | [email protected] | 9.8 | 1.88% | 2019-08-01 | 2024-11-21 |
| CVE-2007-5622 | Double free vulnerability in the ftpprchild function in ftppr in 3proxy 0.5 through 0.5.3i allows remote attackers to cause a denial of service (daemon crash) via multiple OPEN commands to the FTP proxy. | [email protected] | 5.0 | 2.08% | 2007-10-29 | 2026-04-23 |
| CVE-2007-2031 | Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote attackers to execute arbitrary code via crafted transparent requests. | [email protected] | 10.0 | 15.31% | 2007-04-16 | 2026-04-23 |
| CVE-2006-6982 | 3proxy 0.5 to 0.5.2 does not offer NTLM authentication before basic authentication, which might cause browsers with incomplete RFC2616/RFC2617 support to use basic cleartext authentication even if NTLM is available, which makes it easier for attackers to steal credentials. | [email protected] | 5.0 | 0.95% | 2007-02-08 | 2026-04-23 |
| CVE-2006-6981 | 3proxy 0.5 to 0.5.2, when NT-encoded passwords are being used, allows remote attackers to cause a denial of service (blocked account) via unspecified vectors related to NTLM authentication, which causes a password hash to be overwritten. | [email protected] | 5.0 | 1.19% | 2007-02-08 | 2026-04-23 |