Vulnerability index

Browse CVEs

143 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Curl CRITICAL 9.8
CVE-2019-5481EPSS 7%

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

Fix: after 7.65.3
Fix from $2,300 2019-09-16
Curl CRITICAL 9.8
CVE-2019-5482EPSS 18%

Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.

Fix: after 7.65.3
Fix from $2,300 2019-09-16
Curl HIGH 7.8
CVE-2019-5443

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 au…

Fix: after 8.0.17
Fix from $1,950 2019-07-02
Curl CRITICAL 9.1
CVE-2018-16842

Curl versions 7.14.1 through 7.61.1 are vulnerable to a heap-based buffer over-read in the tool_msgs.c:voutf() function that may result in informatio…

Fix: after 7.61.1
Fix from $2,300 2018-10-31
Curl CRITICAL 9.8
CVE-2018-16839EPSS 6%

Curl versions 7.33.0 through 7.61.1 are vulnerable to a buffer overrun in the SASL authentication code that may lead to denial of service.

Fix: after 7.61.1
Fix from $2,300 2018-10-31
Curl CRITICAL 9.8
CVE-2018-16840

A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and clea…

Fix: 7.62.0+
Fix from $2,300 2018-10-31
Curl HIGH 7.5
CVE-2003-1605

curl 7.x before 7.10.7 sends CONNECT proxy credentials to the remote server.

Fix: 7.10.7+
Fix from $1,950 2018-08-23
Curl CRITICAL 9.8
CVE-2016-8619

The function `read_data()` in security.c in curl before version 7.51.0 is vulnerable to memory double free.

Fix: 7.51.0+
Fix from $2,300 2018-08-01
Curl CRITICAL 9.8
CVE-2016-8620

The 'globbing' feature in curl before version 7.51.0 has a flaw that leads to integer overflow and out-of-bounds read via user controlled input.

Fix: 7.51.0+
Fix from $2,300 2018-08-01
Curl HIGH 7.5
CVE-2016-8615

A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent reque…

Fix: 7.51.0+
Fix from $1,950 2018-08-01
Curl HIGH 7.5
CVE-2016-8623

A flaw was found in curl before version 7.51.0. The way curl handles cookies permits other threads to trigger a use-after-free leading to information…

Fix: 7.51.0+
Fix from $1,950 2018-08-01
Curl HIGH 7.5
CVE-2016-8625

curl before version 7.51.0 uses outdated IDNA 2003 standard to handle International Domain Names and this may lead users to potentially and unknowing…

Fix: 7.51.0+
Fix from $1,950 2018-08-01
Curl MEDIUM 5.9
CVE-2016-8616

A flaw was found in curl before version 7.51.0 When re-using a connection, curl was doing case insensitive comparisons of user name and password with…

Fix: 7.51.0+
Fix from $1,600 2018-08-01
Curl HIGH 7.5
CVE-2016-8621EPSS 5%

The `curl_getdate` function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input with one digit short.

Fix: 7.51.0+
Fix from $1,950 2018-07-31
Curl HIGH 7.0
CVE-2016-8617

The base64 encode function in curl before version 7.51.0 is prone to a buffer being under allocated in 32bit systems if it receives at least 1Gb as i…

Fix: 7.51.0+
Fix from $1,950 2018-07-31
Curl CRITICAL 9.8
CVE-2016-8618

The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplicat…

Fix: 7.51.0+
Fix from $2,300 2018-07-31
Libcurl CRITICAL 9.8
CVE-2016-8622

The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to …

Fix: 7.51.0+
Fix from $2,300 2018-07-31
Curl HIGH 7.5
CVE-2016-8624EPSS 6%

curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could in…

Fix: 7.51.0+
Fix from $1,950 2018-07-31
Curl MEDIUM 6.5
CVE-2017-2629

curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validi…

Fix: 7.53.0+
Fix from $1,600 2018-07-27
Libcurl HIGH 7.5
CVE-2017-7468

In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is…

Fix: after 7.53.1
Fix from $1,950 2018-07-16
Curl CRITICAL 9.8
CVE-2018-0500EPSS 6%

Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attac…

Fix: after 7.60.0
Fix from $2,300 2018-07-11
Curl CRITICAL 9.8
CVE-2018-1000300

curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that…

Fix: after 7.59.0
Fix from $2,300 2018-05-24
Curl HIGH 8.1
CVE-2016-9594

curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 32bit random value. Having a …

Fix: 7.52.1+
Fix from $1,950 2018-04-23
Curl HIGH 8.1
CVE-2016-9586

curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() fu…

Fix: 7.52.0+
Fix from $1,950 2018-04-23
Curl CRITICAL 9.8
CVE-2016-9953

The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, al…

Fix: after 7.51.0
Fix from $2,300 2018-03-12
Curl HIGH 8.1
CVE-2016-9952

The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, ma…

Fix: after 7.51.0
Fix from $1,950 2018-03-12
Curl CRITICAL 9.8
CVE-2017-2628

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not refl…

Mitigation only
Fix from $2,300 2018-03-12
Curl CRITICAL 9.8
CVE-2018-1000007EPSS 8%

libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libc…

Fix: after 7.57.0
Fix from $2,300 2018-01-24
Curl CRITICAL 9.8
CVE-2017-8816EPSS 9%

The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow…

Fix: after 7.56.1
Fix from $2,300 2017-11-29
Curl CRITICAL 9.8
CVE-2017-8817EPSS 11%

The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application …

Fix: after 7.56.1
Fix from $2,300 2017-11-29