CVEs (160)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apple HaxxNetapp8Clustered Data Ontap CurlH300s Firmware+5 moreJun 17, 2026 May 26, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A use after free vulnerability exists in curl <v8.1.0 in the way libcurl offers a feature to verify an SSH server's public key using a SHA 256 hash. When this check fails, libcurl would free the memory for the fingerprin...Show more |
5Broadcom FedoraprojectHaxx+2 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareCurl+6 moreJun 17, 2026 Mar 30, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first...Show more |
4Fedoraproject HaxxNetapp+1 more9Active Iq Unified Manager Clustered Data OntapCurl+6 moreJun 17, 2026 Mar 30, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The la...Show more |
5Debian FedoraprojectHaxx+2 more9Clustered Data Ontap CurlDebian Linux+6 moreJun 17, 2026 Feb 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potent...Show more |
3Haxx NetappSplunk8Active Iq Unified Manager Clustered Data OntapCurl+5 moreJun 17, 2026 Feb 23, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support, curl...Show more |
3Haxx NetappSplunk8Active Iq Unified Manager Clustered Data OntapCurl+5 moreJun 17, 2026 Feb 23, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support, curl can be instructed t...Show more |
3Apple HaxxSplunk3Curl MacosUniversal ForwarderJun 17, 2026 Feb 9, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting de...Show more |
4Fedoraproject HaxxNetapp+1 more7Active Iq Unified Manager CurlFedora+4 moreJun 17, 2026 Dec 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even...Show more |
4Apple HaxxNetapp+1 more8Clustered Data Ontap CurlH300s Firmware+5 moreJun 17, 2026 Dec 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the end of the stack-based buffer, and if the...Show more |
5Apple DebianHaxx+2 more9Clustered Data Ontap CurlDebian Linux+6 moreJun 17, 2026 Dec 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was us...Show more |
5Apple FedoraprojectHaxx+2 more9Curl FedoraH300s Firmware+6 moreJun 17, 2026 Oct 29, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels...Show more |
4Apple FedoraprojectHaxx+1 more4Curl FedoraMacos+1 moreJun 17, 2026 Oct 29, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 In curl before 7.86.0, the HSTS check could be bypassed to trick it into staying with HTTP. Using its HSTS support, curl can be instructed to use HTTPS directly (instead of using an insecure cleartext HTTP step) even whe...Show more |
5Apple DebianHaxx+2 more13Bootstrap Os Clustered Data OntapCurl+10 moreJun 17, 2026 Sep 23, 2022 N/A· v4 3.7 LOW· v3 N/A· v2 When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing...Show more |
6Apple DebianFedoraproject+3 more14Bootstrap Os Clustered Data OntapCurl+11 moreJun 17, 2026 Jul 7, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the...Show more |
6Apple DebianFedoraproject+3 more14Bootstrap Os Clustered Data OntapCurl+11 moreJun 17, 2026 Jul 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation...Show more |
6Debian FedoraprojectHaxx+3 more19Bootstrap Os Clustered Data OntapCurl+16 moreJun 17, 2026 Jul 7, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompress...Show more |
7Apple DebianFedoraproject+4 more19Clustered Data Ontap CurlDebian Linux+16 moreJun 17, 2026 Jul 7, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this,...Show more |
3Haxx NetappSplunk10Clustered Data Ontap CurlH300s Firmware+7 moreJun 17, 2026 Jun 2, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given U...Show more |
3Debian HaxxSplunk3Curl Debian LinuxUniversal ForwarderJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttra...Show more |
4Debian HaxxNetapp+1 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS g...Show more |