See how pavuk compares to other vendors in security performance
Multiple buffer overflows in Pavuk before 0.9.32 have unknown attack vectors and impact.
Multiple buffer overflows in the digest authentication functionality in Pavuk 0.9.28-r2 and earlier allow remote attackers to execute arbitrary code.
Stack-based buffer overflow in pavuk 0.9pl28, 0.9pl27, and possibly other versions allows remote web sites to execute arbitrary code via a long HTTP Location header.