Vulnerabilities (CVE)

Filtered by vendor Gnu Subscribe
Filtered by product Wget
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2004-1487 1 Gnu 1 Wget 2026-06-16 5.0 MEDIUM N/A
wget 1.8.x and 1.9.x allows a remote malicious web server to overwrite certain files via a redirection URL containing a ".." that resolves to the IP address of the malicious server, which bypasses wget's filtering for ".." sequences.
CVE-2002-1344 2 Gnu, Sun 2 Wget, Cobalt Raq Xtr 2026-06-16 5.0 MEDIUM N/A
Directory traversal vulnerability in wget before 1.8.2-4 allows a remote FTP server to create or overwrite files as the wget user via filenames containing (1) /absolute/path or (2) .. (dot dot) sequences.
CVE-1999-0402 1 Gnu 1 Wget 2026-06-16 5.0 MEDIUM N/A
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.