Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2017-8818
curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possi…
Curl
Patch available
HIGH 7.5
CVE-2017-1000254EPSS 8%
libcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in (anonymous or not…
Libcurl
Patch available
MEDIUM 6.5
CVE-2017-1000099
When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers. The code doin…
Libcurl
Patch available
MEDIUM 6.5
CVE-2017-1000100
When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is trunca…
Libcurl
Patch available
MEDIUM 6.5
CVE-2017-1000101
curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfer…
Curl
Mitigation only
MEDIUM 5.3
CVE-2017-9502
In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol li…
Curl
after 7.54.0
HIGH 7.8
CVE-2016-4802
Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to exe…
Curl
after 7.49.0
MEDIUM 5.3
CVE-2016-3739EPSS 7%
The (1) mbed_connect_step1 function in lib/vtls/mbedtls.c and (2) polarssl_connect_step1 function in lib/vtls/polarssl.c in cURL and libcurl before 7…
Curl
Patch available
HIGH 7.3
CVE-2016-0755EPSS 9%
The ConnectionExists function in lib/url.c in libcurl before 7.47.0 does not properly re-use NTLM-authenticated proxy connections, which might allow …
Curl
after 7.46.0
MEDIUM 5.3
CVE-2016-0754
cURL before 7.47.0 on Windows allows attackers to write to arbitrary files in the current working directory on a different drive via a colon in a rem…
Curl
after 7.46.0
MEDIUM 6.4
CVE-2015-3237EPSS 8%
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cau…
Curl
after 7.5.3.1
MEDIUM 5.0
CVE-2015-3236EPSS 7%
cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset…
Curl
Patch available
MEDIUM 5.0
CVE-2015-3153EPSS 7%
The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow re…
Curl
after 12.1.3
HIGH 9.0
CVE-2015-3144EPSS 11%
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a de…
Curl
after 3.0.22
MEDIUM 5.0
CVE-2015-3143EPSS 13%
cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unau…
Curl
after 10.9.5
MEDIUM 5.0
CVE-2014-3620
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a …
Curl
after 10.10.4
MEDIUM 5.0
CVE-2014-3613EPSS 7%
cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send…
Curl
after 10.10.4
MEDIUM 6.4
CVE-2014-0138EPSS 5%
The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8)…
Curl
Mitigation only
MEDIUM 5.8
CVE-2014-0139
cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject'…
Curl
Mitigation only
MEDIUM 6.8
CVE-2013-2174EPSS 11%
Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause…
Curl
Patch available
MEDIUM 5.0
CVE-2013-1944
The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remot…
Curl
after 7.29.0
HIGH 7.5
CVE-2013-0249EPSS 21%
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when ne…
Curl
No fix yet
HIGH 8.8
CVE-2005-0490EPSS 6%
Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrar…
Curl
Patch available