CVE-2021-22925
- EPSS 4.93%
- Veröffentlicht 05.08.2021 21:15:11
- Zuletzt bearbeitet 16.04.2026 17:16:52
curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be ...
CVE-2021-22926
- EPSS 9.82%
- Veröffentlicht 05.08.2021 21:15:11
- Zuletzt bearbeitet 28.05.2026 21:16:27
libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Trans...
CVE-2021-22898
- EPSS 4.39%
- Veröffentlicht 11.06.2021 16:15:11
- Zuletzt bearbeitet 16.04.2026 14:16:11
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NE...
CVE-2021-22901
- EPSS 60.12%
- Veröffentlicht 11.06.2021 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:50:52
curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentia...
CVE-2021-22897
- EPSS 2.98%
- Veröffentlicht 11.06.2021 16:15:10
- Zuletzt bearbeitet 28.05.2026 21:16:27
curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" ...
CVE-2020-8169
- EPSS 3.43%
- Veröffentlicht 14.12.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:38:25
curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s).
CVE-2020-8177
- EPSS 1.24%
- Veröffentlicht 14.12.2020 20:15:13
- Zuletzt bearbeitet 15.04.2026 21:17:03
curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.
CVE-2020-8284
- EPSS 3.85%
- Veröffentlicht 14.12.2020 20:15:13
- Zuletzt bearbeitet 16.04.2026 15:16:42
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed,...
CVE-2016-4606
- EPSS 3.4%
- Veröffentlicht 21.02.2020 02:15:10
- Zuletzt bearbeitet 21.11.2024 02:52:36
Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized act...
CVE-2019-5481
- EPSS 7.27%
- Veröffentlicht 16.09.2019 19:15:10
- Zuletzt bearbeitet 16.04.2026 15:16:40
Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.