Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Curl HIGH 7.0
CVE-2025-0665

libcurl would wrongly close the same eventfd file descriptor twice when taking down a connection channel after having completed a threaded name resol…

No fix yet
Fix from $1,950 2025-02-05
Curl MEDIUM 5.3
CVE-2024-0853

curl inadvertently kept the SSL session ID for connections in its cache even when the verify status (*OCSP stapling*) test failed. A subsequent trans…

No fix yet
Fix from $1,600 2024-02-03
Libcurl MEDIUM 5.9
CVE-2023-27537

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considera…

No fix yet
Fix from $1,600 2023-03-30
Curl CRITICAL 9.8
CVE-2017-2628

curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not refl…

Mitigation only
Fix from $2,300 2018-03-12
Curl MEDIUM 6.5
CVE-2017-1000101

curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfer…

Mitigation only
Fix from $1,600 2017-10-05
Curl MEDIUM 6.4
CVE-2014-0138EPSS 5%

The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8)…

Mitigation only
Fix from $1,600 2014-04-15
Curl MEDIUM 5.8
CVE-2014-0139

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject'…

Mitigation only
Fix from $1,600 2014-04-15
Curl HIGH 7.5
CVE-2013-0249EPSS 21%

Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when ne…

No fix yet
Fix from $1,950 2013-03-08