4.6
CVE-2005-4077
- EPSS 0.27%
- Veröffentlicht 08.12.2005 01:03:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple off-by-one errors in the cURL library (libcurl) 7.11.2 through 7.15.0 allow local users to trigger a buffer overflow and cause a denial of service or bypass PHP security restrictions via certain URLs that (1) are malformed in a way that prevents a terminating null byte from being added to either a hostname or path buffer, or (2) contain a "?" separator in the hostname portion, which causes a "/" to be prepended to the resulting string.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Daniel Stenberg ≫ Curl Version7.11.2
Daniel Stenberg ≫ Curl Version7.12
Daniel Stenberg ≫ Curl Version7.12.1
Daniel Stenberg ≫ Curl Version7.12.2
Daniel Stenberg ≫ Curl Version7.12.3
Daniel Stenberg ≫ Curl Version7.13
Daniel Stenberg ≫ Curl Version7.13.1
Daniel Stenberg ≫ Curl Version7.13.2
Daniel Stenberg ≫ Curl Version7.14
Daniel Stenberg ≫ Curl Version7.14.1
Daniel Stenberg ≫ Curl Version7.15
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.499 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|