Known vulnerabilities in wget (Alpine package)

Software CPE: cpe:2.3:o:alpine:wget_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 10
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting wget (Alpine package) wget (Alpine package) is affected by 10 known vulnerabilities: 5 high, 1 medium, 4 low Critical High Medium Low

Vulnerabilities (10)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU18143 - Memory corruption
CVE-2019-5953
CWE-119 High
No
No
1.20.3-r0 06.04.2019 SB2019040601
SB2019040602
SB2019040810
and 14 more
#VU16783 - Exposure of sensitive information to an unauthorized actor
CVE-2018-20483
CWE-200 Low
No
No
1.20.1-r0 02.01.2019 SB2018122510
SB2019011803
SB2019020808
and 9 more
#VU12432 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2018-0494
CWE-74 Low
Available
No
1.18-r3, 1.18-r4 08.05.2018 SB2018050804
SB2018051102
SB2018051107
and 10 more
#VU8989 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2017-6508
CWE-113 Low
No
No
1.17.1-r2 30.10.2017 SB2017103010
SB2017083115
SB2017062020
and 4 more
#VU8960 - Heap-based Buffer Overflow
CVE-2017-13090
CWE-122 High
No
No
1.18-r2, 1.18-r3 27.10.2017 SB2017102703
SB2017102707
SB2017102801
and 12 more
#VU8959 - Heap-based Buffer Overflow
CVE-2017-13089
CWE-122 High
No
No
1.18-r2, 1.18-r3 26.10.2017 SB2017102703
SB2017102707
SB2017102801
and 13 more
#VU32275 - Security Features
CVE-2016-4971
CWE-254 High
Available
No
1.17.1-r1, 1.18-r0 30.06.2016 SB2016063014
SB2016070507
SB2016071408
and 7 more
#VU32477 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2014-4877
CWE-22 High
Available
No
1.16-r0 29.10.2014 SB2014102902
SB2014111202
SB2014111203
and 6 more
#VU33127 - Improper Link Resolution Before File Access ('Link Following')
CVE-2011-3616
CWE-59 Low
No
No
1.12-r3, 1.12-r4 04.11.2011 SB2011101704
SB2011101302
#VU33335 - Improper input validation
CVE-2010-2252
CWE-20 Medium
No
No
1.12-r3, 1.12-r4 06.07.2010 SB2010070601
SB2011101703
SB2011101301