CVE-2018-1000301
- EPSS 5.93%
- Veröffentlicht 24.05.2018 13:29:01
- Zuletzt bearbeitet 15.04.2026 21:16:59
curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP...
CVE-2016-9594
- EPSS 2.31%
- Veröffentlicht 23.04.2018 19:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:28
curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 32bit random value. Having a weak or virtually non-existent random value makes the operations that use it vulnerable.
CVE-2016-9586
- EPSS 4.94%
- Veröffentlicht 23.04.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:01:26
curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary...
CVE-2018-1000120
- EPSS 11.82%
- Veröffentlicht 14.03.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:43
A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.
CVE-2018-1000121
- EPSS 9.38%
- Veröffentlicht 14.03.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:43
A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service
CVE-2018-1000122
- EPSS 9.21%
- Veröffentlicht 14.03.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:43
A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage
CVE-2016-9952
- EPSS 1.3%
- Veröffentlicht 12.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:02:03
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted wildcard SAN in...
CVE-2016-9953
- EPSS 1.83%
- Veröffentlicht 12.03.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:02:04
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly...
CVE-2017-2628
- EPSS 3.87%
- Veröffentlicht 12.03.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:23:51
curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by USE_HTTP_NEGOTIATE. This issue ...
CVE-2018-1000007
- EPSS 8.03%
- Veröffentlicht 24.01.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 03:39:24
libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow r...