Haxx / Libcurl
61 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-0725 | gzip integer overflow | HIGH | 7.3 | Feb 5, 2025 |
| CVE-2024-32928 | The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle atta… | MEDIUM | 5.9 | Aug 19, 2024 |
| CVE-2024-7264 | ASN.1 date parser overread | MEDIUM | 6.5 | Jul 31, 2024 |
| CVE-2024-6874 | macidn punycode buffer overread | MEDIUM | 5.3 | Jul 24, 2024 |
| CVE-2024-6197 | freeing stack buffer in utf8asn1str | HIGH | 7.5 | Jul 24, 2024 |
| CVE-2023-38545 | curl: heap based buffer overflow in the SOCKS5 proxy handshake | CRITICAL | 9.8 | Oct 18, 2023 |
| CVE-2023-38546 | curl: cookie injection with none file | LOW | 3.7 | Oct 18, 2023 |
| CVE-2023-27538 | curl: SSH connection too eager reuse still | HIGH | 7.7 | Mar 30, 2023 |
| CVE-2023-27537 | curl: HSTS double-free | MEDIUM | 5.9 | Mar 30, 2023 |
| CVE-2023-27536 | curl: GSS delegation too eager connection re-use | MEDIUM | 5.9 | Mar 30, 2023 |
| CVE-2023-27535 | curl: FTP too eager connection reuse | MEDIUM | 5.9 | Mar 30, 2023 |
| CVE-2021-22945 | curl: use-after-free and double-free in MQTT sending | CRITICAL | 9.1 | Sep 23, 2021 |
| CVE-2021-22924 | curl: Bad connection reuse due to flawed path name checks | LOW | 3.7 | Aug 5, 2021 |
| CVE-2021-22890 | curl: TLS 1.3 session ticket mix-up with HTTPS proxy host | MEDIUM | 4.3 | Apr 1, 2021 |
| CVE-2021-22876 | curl: Leak of authentication credentials in URL via automatic Referer | MEDIUM | 5.3 | Apr 1, 2021 |
| CVE-2020-8286 | curl: Inferior OCSP verification | HIGH | 7.5 | Dec 14, 2020 |
| CVE-2020-8231 | curl: Expired pointer dereference via multi API with CURLOPT_CONNECT_ONLY option set | HIGH | 7.5 | Dec 14, 2020 |
| CVE-2020-8285 | curl: Malicious FTP server can trigger stack overflow when CURLOPT_CHUNK_BGN_FUNCTION is used | HIGH | 7.5 | Dec 14, 2020 |
| CVE-2019-5436 | curl: TFTP receive heap buffer overflow in tftp_receive_packet() function | HIGH | 7.8 | May 28, 2019 |
| CVE-2019-3823 | curl: SMTP end-of-response out-of-bounds read | HIGH | 7.5 | Feb 6, 2019 |
| CVE-2019-3822 | curl: NTLMv2 type-3 header stack buffer overflow | CRITICAL | 9.8 | Feb 6, 2019 |
| CVE-2018-16890 | curl: NTLM type-2 heap out-of-bounds buffer read | HIGH | 7.5 | Feb 6, 2019 |
| CVE-2018-14618 | curl: NTLM password overflow via integer overflow | CRITICAL | 9.8 | Sep 5, 2018 |
| CVE-2016-8622 | curl: URL unescape heap overflow via integer truncation | CRITICAL | 9.8 | Jul 31, 2018 |
| CVE-2017-7468 | curl: TLS session resumption client cert bypass | HIGH | 7.5 | Jul 16, 2018 |
Showing 1 to 25 of 61 CVEs