Curl

Libcurl

5 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.15%
  • Veröffentlicht 27.03.2024 08:15:41
  • Zuletzt bearbeitet 30.07.2025 19:42:21

libcurl did not check the server certificate of TLS connections done to a host specified as an IP address, when built to use mbedTLS. libcurl would wrongly avoid using the set hostname function when the specified hostname was given as an IP address,...

  • EPSS 6.54%
  • Veröffentlicht 13.04.2012 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack ...

  • EPSS 4.76%
  • Veröffentlicht 19.03.2010 19:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of se...

  • EPSS 7.33%
  • Veröffentlicht 14.08.2009 15:16:27
  • Zuletzt bearbeitet 09.04.2025 00:30:58

lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof a...

Exploit
  • EPSS 3.37%
  • Veröffentlicht 05.03.2009 02:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or o...