6.4

CVE-2014-0138

The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which might allow context-dependent attackers to connect as other users via a request, a similar issue to CVE-2014-0015.

Data is provided by the National Vulnerability Database (NVD)
HaxxCurl Version7.10.6
HaxxCurl Version7.10.7
HaxxCurl Version7.10.8
HaxxCurl Version7.11.0
HaxxCurl Version7.11.1
HaxxCurl Version7.11.2
HaxxCurl Version7.12.0
HaxxCurl Version7.12.1
HaxxCurl Version7.12.2
HaxxCurl Version7.12.3
HaxxCurl Version7.13.0
HaxxCurl Version7.13.1
HaxxCurl Version7.13.2
HaxxCurl Version7.14.0
HaxxCurl Version7.14.1
HaxxCurl Version7.15.0
HaxxCurl Version7.15.1
HaxxCurl Version7.15.2
HaxxCurl Version7.15.3
HaxxCurl Version7.15.4
HaxxCurl Version7.15.5
HaxxCurl Version7.16.0
HaxxCurl Version7.16.1
HaxxCurl Version7.16.2
HaxxCurl Version7.16.3
HaxxCurl Version7.16.4
HaxxCurl Version7.17.0
HaxxCurl Version7.17.1
HaxxCurl Version7.18.0
HaxxCurl Version7.18.1
HaxxCurl Version7.18.2
HaxxCurl Version7.19.0
HaxxCurl Version7.19.1
HaxxCurl Version7.19.2
HaxxCurl Version7.19.3
HaxxCurl Version7.19.4
HaxxCurl Version7.19.5
HaxxCurl Version7.19.6
HaxxCurl Version7.19.7
HaxxCurl Version7.20.0
HaxxCurl Version7.20.1
HaxxCurl Version7.21.0
HaxxCurl Version7.21.1
HaxxCurl Version7.21.2
HaxxCurl Version7.21.3
HaxxCurl Version7.21.4
HaxxCurl Version7.21.5
HaxxCurl Version7.21.6
HaxxCurl Version7.21.7
HaxxCurl Version7.22.0
HaxxCurl Version7.23.0
HaxxCurl Version7.23.1
HaxxCurl Version7.24.0
HaxxCurl Version7.25.0
HaxxCurl Version7.26.0
HaxxCurl Version7.27.0
HaxxCurl Version7.28.0
HaxxCurl Version7.28.1
HaxxCurl Version7.29.0
HaxxCurl Version7.30.0
HaxxCurl Version7.31.0
HaxxCurl Version7.32.0
HaxxCurl Version7.33.0
HaxxCurl Version7.34.0
HaxxCurl Version7.35.0
HaxxLibcurl Version7.10.6
HaxxLibcurl Version7.10.7
HaxxLibcurl Version7.10.8
HaxxLibcurl Version7.11.0
HaxxLibcurl Version7.11.1
HaxxLibcurl Version7.11.2
HaxxLibcurl Version7.12.0
HaxxLibcurl Version7.12.1
HaxxLibcurl Version7.12.2
HaxxLibcurl Version7.12.3
HaxxLibcurl Version7.13.0
HaxxLibcurl Version7.13.1
HaxxLibcurl Version7.13.2
HaxxLibcurl Version7.14.0
HaxxLibcurl Version7.14.1
HaxxLibcurl Version7.15.0
HaxxLibcurl Version7.15.1
HaxxLibcurl Version7.15.2
HaxxLibcurl Version7.15.3
HaxxLibcurl Version7.15.4
HaxxLibcurl Version7.15.5
HaxxLibcurl Version7.16.0
HaxxLibcurl Version7.16.1
HaxxLibcurl Version7.16.2
HaxxLibcurl Version7.16.3
HaxxLibcurl Version7.16.4
HaxxLibcurl Version7.17.0
HaxxLibcurl Version7.17.1
HaxxLibcurl Version7.18.0
HaxxLibcurl Version7.18.1
HaxxLibcurl Version7.18.2
HaxxLibcurl Version7.19.0
HaxxLibcurl Version7.19.1
HaxxLibcurl Version7.19.2
HaxxLibcurl Version7.19.3
HaxxLibcurl Version7.19.4
HaxxLibcurl Version7.19.5
HaxxLibcurl Version7.19.6
HaxxLibcurl Version7.19.7
HaxxLibcurl Version7.20.0
HaxxLibcurl Version7.20.1
HaxxLibcurl Version7.21.0
HaxxLibcurl Version7.21.1
HaxxLibcurl Version7.21.2
HaxxLibcurl Version7.21.3
HaxxLibcurl Version7.21.4
HaxxLibcurl Version7.21.5
HaxxLibcurl Version7.21.6
HaxxLibcurl Version7.21.7
HaxxLibcurl Version7.22.0
HaxxLibcurl Version7.23.0
HaxxLibcurl Version7.23.1
HaxxLibcurl Version7.24.0
HaxxLibcurl Version7.25.0
HaxxLibcurl Version7.26.0
HaxxLibcurl Version7.27.0
HaxxLibcurl Version7.28.0
HaxxLibcurl Version7.28.1
HaxxLibcurl Version7.29.0
HaxxLibcurl Version7.30.0
HaxxLibcurl Version7.31.0
HaxxLibcurl Version7.32.0
HaxxLibcurl Version7.33.0
HaxxLibcurl Version7.34.0
HaxxLibcurl Version7.35.0
DebianDebian Linux Version7.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.27% 0.788
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.