Haxx

Curl

121 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.28%
  • Published 11.07.2018 13:29:00
  • Last modified 21.11.2024 03:38:21

Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain settings (i.e., use of a nons...

  • EPSS 0.95%
  • Published 24.05.2018 13:29:01
  • Last modified 21.11.2024 03:39:58

curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when closing down an FTP connection wit...

  • EPSS 2.57%
  • Published 24.05.2018 13:29:01
  • Last modified 21.11.2024 03:39:58

curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP...

  • EPSS 0.95%
  • Published 23.04.2018 19:29:00
  • Last modified 21.11.2024 03:01:28

curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 32bit random value. Having a weak or virtually non-existent random value makes the operations that use it vulnerable.

  • EPSS 0.84%
  • Published 23.04.2018 18:29:00
  • Last modified 21.11.2024 03:01:26

curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from the outside without necessary...

  • EPSS 1.64%
  • Published 14.03.2018 18:29:00
  • Last modified 21.11.2024 03:39:43

A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse.

  • EPSS 2.81%
  • Published 14.03.2018 18:29:00
  • Last modified 21.11.2024 03:39:43

A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service

  • EPSS 1.75%
  • Published 14.03.2018 18:29:00
  • Last modified 21.11.2024 03:39:43

A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage

  • EPSS 1.01%
  • Published 12.03.2018 21:29:00
  • Last modified 21.11.2024 03:02:03

The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted wildcard SAN in...

  • EPSS 1.85%
  • Published 12.03.2018 21:29:00
  • Last modified 21.11.2024 03:02:04

The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly...