#wget clear

CVE-2019-5953: wget heap buffer overflow in do_conversion via incorrect E2BIG handling

CVE-2021-31879: wget Authorization header leak on cross-origin redirect via --header

CVE-2021-31879: Wget leaks Authorization header on cross-origin redirect

CVE-2018-20483: wget leaks URL credentials into POSIX extended file attributes (xattrs)

CVE-2018-20483: wget --xattr leaks URL credentials into user.xdg.origin.url extended attribute

CVE-2017-13089: wget skip_short_body stack overflow via negative HTTP chunk size (signed strtol + SIZE_MAX read)

CVE-2017-13089: wget skip_short_body() stack overflow via negative chunked size

CVE-2024-38428: wget url_skip_credentials semicolon causes hostname confusion

CVE-2024-38428: GNU Wget url_skip_credentials mishandles ';' in userinfo, enabling hostname confusion

CVE-2024-38428: URL parser hostname confusion via multiple @ characters in userinfo

CVE-2019-5953: wget 1.20.1 heap buffer overflow in reencode_escapes() URL handling

CVE-2019-5953: heap buffer overflow in wget iri.c do_conversion

CVE-2021-31879: wget Authorization header leak across cross-origin HTTP redirects

CVE-2021-31879: wget leaks Authorization across origin on redirect

CVE-2021-31879: HTTP Redirect Authorization Header Leak in Wget v1.21

CVE-2018-20483: wget --xattr leaks URL credentials into extended file attributes

CVE-2018-20483: wget --xattr leaks Basic-auth credentials via user.xdg.origin.url

CVE-2018-20483: Information Leak via Extended File Attributes in wget

CVE-2017-13089: wget skip_short_body stack overflow via negative chunked transfer encoding size

CVE-2017-13089: Stack-overflow in wget HTTP chunked transfer encoding parsing