Vulnerability index

Browse CVEs

143 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Curl CRITICAL 9.8
CVE-2017-8818

curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possi…

Patch available
Fix from $2,300 2017-11-29
Libcurl HIGH 7.5
CVE-2017-1000254EPSS 8%

libcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in (anonymous or not…

Patch available
Fix from $1,950 2017-10-06
Libcurl MEDIUM 6.5
CVE-2017-1000099

When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers. The code doin…

Patch available
Fix from $1,600 2017-10-05
Libcurl MEDIUM 6.5
CVE-2017-1000100

When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is trunca…

Patch available
Fix from $1,600 2017-10-05
Curl MEDIUM 6.5
CVE-2017-1000101

curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfer…

Mitigation only
Fix from $1,600 2017-10-05
Curl MEDIUM 5.3
CVE-2017-9502

In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol li…

Fix: after 7.54.0
Fix from $1,600 2017-06-14
Curl HIGH 7.8
CVE-2016-4802

Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to exe…

Fix: after 7.49.0
Fix from $1,950 2016-06-24
Curl MEDIUM 5.3
CVE-2016-3739EPSS 7%

The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7…

Patch available
Fix from $1,600 2016-05-20
Curl HIGH 7.3
CVE-2016-0755EPSS 9%

The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow …

Fix: after 7.46.0
Fix from $1,950 2016-01-29
Curl MEDIUM 5.3
CVE-2016-0754

cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a different drive via a colon in a rem…

Fix: after 7.46.0
Fix from $1,600 2016-01-29
Curl MEDIUM 6.4
CVE-2015-3237EPSS 8%

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cau…

Fix: after 7.5.3.1
Fix from $1,600 2015-06-22
Curl MEDIUM 5.0
CVE-2015-3236EPSS 7%

cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset…

Patch available
Fix from $1,600 2015-06-22
Curl MEDIUM 5.0
CVE-2015-3153EPSS 7%

The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow re…

Fix: after 12.1.3
Fix from $1,600 2015-05-01
Curl HIGH 9.0
CVE-2015-3144EPSS 11%

The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a de…

Fix: after 3.0.22
Fix from $1,950 2015-04-24
Curl MEDIUM 5.0
CVE-2015-3143EPSS 13%

cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unau…

Fix: after 10.9.5
Fix from $1,600 2015-04-24
Curl MEDIUM 5.0
CVE-2014-3620

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a …

Fix: after 10.10.4
Fix from $1,600 2014-11-18
Curl MEDIUM 5.0
CVE-2014-3613EPSS 7%

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send…

Fix: after 10.10.4
Fix from $1,600 2014-11-18
Curl MEDIUM 6.4
CVE-2014-0138EPSS 5%

The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8)…

Mitigation only
Fix from $1,600 2014-04-15
Curl MEDIUM 5.8
CVE-2014-0139

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject'…

Mitigation only
Fix from $1,600 2014-04-15
Curl MEDIUM 6.8
CVE-2013-2174EPSS 11%

Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause…

Patch available
Fix from $1,600 2013-07-31
Curl MEDIUM 5.0
CVE-2013-1944

The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remot…

Fix: after 7.29.0
Fix from $1,600 2013-04-29
Curl HIGH 7.5
CVE-2013-0249EPSS 21%

Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when ne…

No fix yet
Fix from $1,950 2013-03-08
Curl HIGH 8.8
CVE-2005-0490EPSS 6%

Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrar…

Patch available
Fix from $1,950 2005-05-02