Haxx

Curl

169 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 4.93%
  • Veröffentlicht 05.08.2021 21:15:11
  • Zuletzt bearbeitet 16.04.2026 17:16:52

curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be ...

Exploit
  • EPSS 9.82%
  • Veröffentlicht 05.08.2021 21:15:11
  • Zuletzt bearbeitet 28.05.2026 21:16:27

libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Trans...

Exploit
  • EPSS 4.39%
  • Veröffentlicht 11.06.2021 16:15:11
  • Zuletzt bearbeitet 16.04.2026 14:16:11

curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NE...

Exploit
  • EPSS 60.12%
  • Veröffentlicht 11.06.2021 16:15:11
  • Zuletzt bearbeitet 21.11.2024 05:50:52

curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentia...

Exploit
  • EPSS 2.98%
  • Veröffentlicht 11.06.2021 16:15:10
  • Zuletzt bearbeitet 28.05.2026 21:16:27

curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" ...

Exploit
  • EPSS 3.43%
  • Veröffentlicht 14.12.2020 20:15:13
  • Zuletzt bearbeitet 21.11.2024 05:38:25

curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).

Exploit
  • EPSS 1.24%
  • Veröffentlicht 14.12.2020 20:15:13
  • Zuletzt bearbeitet 15.04.2026 21:17:03

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

  • EPSS 3.85%
  • Veröffentlicht 14.12.2020 20:15:13
  • Zuletzt bearbeitet 16.04.2026 15:16:42

A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed,...

  • EPSS 3.4%
  • Veröffentlicht 21.02.2020 02:15:10
  • Zuletzt bearbeitet 21.11.2024 02:52:36

Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized act...

  • EPSS 7.27%
  • Veröffentlicht 16.09.2019 19:15:10
  • Zuletzt bearbeitet 16.04.2026 15:16:40

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.