5

CVE-2013-1944

The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HaxxCurl Version <= 7.29.0
HaxxCurl Version6.0
HaxxCurl Version6.1
HaxxCurl Version6.1 Updatebeta
HaxxCurl Version6.2
HaxxCurl Version6.3
HaxxCurl Version6.3.1
HaxxCurl Version6.4
HaxxCurl Version6.5
HaxxCurl Version6.5.1
HaxxCurl Version6.5.2
HaxxCurl Version7.1
HaxxCurl Version7.1.1
HaxxCurl Version7.2
HaxxCurl Version7.2.1
HaxxCurl Version7.3
HaxxCurl Version7.4
HaxxCurl Version7.4.1
HaxxCurl Version7.4.2
HaxxCurl Version7.5.1
HaxxCurl Version7.5.2
HaxxCurl Version7.6
HaxxCurl Version7.6.1
HaxxCurl Version7.7
HaxxCurl Version7.7.1
HaxxCurl Version7.7.2
HaxxCurl Version7.7.3
HaxxCurl Version7.8
HaxxCurl Version7.8.1
HaxxCurl Version7.9
HaxxCurl Version7.9.1
HaxxCurl Version7.9.2
HaxxCurl Version7.9.3
HaxxCurl Version7.9.4
HaxxCurl Version7.9.5
HaxxCurl Version7.9.6
HaxxCurl Version7.9.7
HaxxCurl Version7.9.8
HaxxCurl Version7.10
HaxxCurl Version7.10.1
HaxxCurl Version7.10.2
HaxxCurl Version7.10.3
HaxxCurl Version7.10.4
HaxxCurl Version7.10.5
HaxxCurl Version7.10.6
HaxxCurl Version7.10.7
HaxxCurl Version7.10.8
HaxxCurl Version7.11.0
HaxxCurl Version7.11.1
HaxxCurl Version7.11.2
HaxxCurl Version7.12.0
HaxxCurl Version7.12.1
HaxxCurl Version7.12.2
HaxxCurl Version7.12.3
HaxxCurl Version7.13.0
HaxxCurl Version7.13.1
HaxxCurl Version7.13.2
HaxxCurl Version7.14.0
HaxxCurl Version7.14.1
HaxxCurl Version7.15.0
HaxxCurl Version7.15.1
HaxxCurl Version7.15.2
HaxxCurl Version7.15.3
HaxxCurl Version7.15.4
HaxxCurl Version7.15.5
HaxxCurl Version7.16.0
HaxxCurl Version7.16.1
HaxxCurl Version7.16.2
HaxxCurl Version7.16.3
HaxxCurl Version7.16.4
HaxxCurl Version7.17.0
HaxxCurl Version7.17.1
HaxxCurl Version7.18.0
HaxxCurl Version7.18.1
HaxxCurl Version7.18.2
HaxxCurl Version7.19.0
HaxxCurl Version7.19.1
HaxxCurl Version7.19.2
HaxxCurl Version7.19.3
HaxxCurl Version7.19.4
HaxxCurl Version7.19.5
HaxxCurl Version7.19.6
HaxxCurl Version7.19.7
HaxxCurl Version7.20.0
HaxxCurl Version7.20.1
HaxxCurl Version7.21.0
HaxxCurl Version7.21.1
HaxxCurl Version7.21.2
HaxxCurl Version7.21.3
HaxxCurl Version7.21.4
HaxxCurl Version7.21.5
HaxxCurl Version7.21.6
HaxxCurl Version7.21.7
HaxxCurl Version7.22.0
HaxxCurl Version7.23.0
HaxxCurl Version7.23.1
HaxxCurl Version7.24.0
HaxxCurl Version7.25.0
HaxxCurl Version7.26.0
HaxxCurl Version7.27.0
HaxxCurl Version7.28.0
HaxxCurl Version7.28.1
HaxxLibcurl Version <= 7.29.0
HaxxLibcurl Version7.14.0
HaxxLibcurl Version7.14.1
HaxxLibcurl Version7.15.0
HaxxLibcurl Version7.15.1
HaxxLibcurl Version7.15.2
HaxxLibcurl Version7.15.3
HaxxLibcurl Version7.15.4
HaxxLibcurl Version7.15.5
HaxxLibcurl Version7.16.0
HaxxLibcurl Version7.16.2
HaxxLibcurl Version7.16.3
HaxxLibcurl Version7.16.4
HaxxLibcurl Version7.17.0
HaxxLibcurl Version7.17.1
HaxxLibcurl Version7.18.0
HaxxLibcurl Version7.18.2
HaxxLibcurl Version7.19.3
HaxxLibcurl Version7.20.0
HaxxLibcurl Version7.21.2
HaxxLibcurl Version7.22.0
HaxxLibcurl Version7.23.0
HaxxLibcurl Version7.28.0
HaxxLibcurl Version7.28.1
CanonicalUbuntu Linux Version8.04 Update- Editionlts
CanonicalUbuntu Linux Version10.04 Update- Editionlts
CanonicalUbuntu Linux Version11.10
CanonicalUbuntu Linux Version12.04 Update- Editionlts
CanonicalUbuntu Linux Version12.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.48% 0.847
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.