Vulnerabilities
Vulnerable Software
In uriparser before 1.0.2, the function family EqualsUri can misclassify two unequal URIs as equal.
CVSS Score
2.9
EPSS Score
0.0
Published
2026-05-08
In uriparser before 1.0.2, there is pointer difference truncation to int in various places.
CVSS Score
2.9
EPSS Score
0.0
Published
2026-05-08
uriparser before 1.0.1 has numeric truncation in text range comparison, if an application accepts URIs with a length in gigabytes.
CVSS Score
5.1
EPSS Score
0.0
Published
2026-04-27
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
CVSS Score
8.6
EPSS Score
0.005
Published
2024-05-03
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
CVSS Score
5.9
EPSS Score
0.005
Published
2024-05-03
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-01-06
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-01-06
URI_FUNC() in UriParse.c in uriparser before 0.9.1 has an out-of-bounds read (in uriParse*Ex* functions) for an incomplete URI with an IPv6 address containing an embedded IPv4 address, such as a "//[::44.1" address.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-01-16
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an out-of-bounds write via a uriComposeQuery* or uriComposeQueryEx* function because the '&' character is mishandled in certain contexts.
CVSS Score
9.8
EPSS Score
0.006
Published
2018-11-12
An issue was discovered in uriparser before 0.9.0. UriQuery.c allows an integer overflow via a uriComposeQuery* or uriComposeQueryEx* function because of an unchecked multiplication.
CVSS Score
9.8
EPSS Score
0.007
Published
2018-11-12


Contact Us

Shodan ® - All rights reserved