CVEs (160)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Haxx NetappSplunk10Clustered Data Ontap CurlH300s Firmware+7 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL lik...Show more |
3Haxx NetappSplunk11Clustered Data Ontap CurlH300s Firmware+8 moreJun 17, 2026 Jun 2, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Publ...Show more |
4Haxx NetappOracle+1 more14Active Iq Unified Manager Bh500s FirmwareClustered Data Ontap+11 moreJun 17, 2026 Jun 2, 2022 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`. |
6Brocade DebianFedoraproject+3 more13Clustered Data Ontap CurlDebian Linux+10 moreJun 17, 2026 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. |
5Brocade DebianHaxx+2 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. |
5Brocade DebianHaxx+2 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authenticat...Show more |
5Brocade DebianHaxx+2 more12Bootstrap Os Clustered Data OntapCurl+9 moreJun 17, 2026 May 26, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the...Show more |
8Apple DebianFedoraproject+5 more26Cloud Backup Clustered Data OntapCommerce Guided Search+23 moreJun 17, 2026 Sep 29, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl woul...Show more |
8Apple DebianFedoraproject+5 more29Cloud Backup Clustered Data OntapCommerce Guided Search+26 moreJun 17, 2026 Sep 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLU...Show more |
5Haxx NetappOracle+2 more19Active Iq Unified Manager Clustered Data OntapCurl+16 moreJun 17, 2026 Aug 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS n...Show more |
7Apple FedoraprojectHaxx+4 more20Cloud Backup Clustered Data OntapCurl+17 moreJun 17, 2026 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_EN...Show more |
6Fedoraproject HaxxNetapp+3 more16Cloud Backup Clustered Data OntapCurl+13 moreJun 17, 2026 Aug 5, 2021 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers fr...Show more |
6Fedoraproject HaxxNetapp+3 more16Cloud Backup Clustered Data OntapCurl+13 moreJun 17, 2026 Aug 5, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentf...Show more |
5Haxx NetappOracle+2 more26Active Iq Unified Manager Cloud BackupCommunications Cloud Native Core Binding Support Function+23 moreJun 17, 2026 Jun 11, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortu...Show more |
6Debian FedoraprojectHaxx+3 more12Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+9 moreJun 17, 2026 Jun 11, 2021 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in th...Show more |
5Haxx NetappOracle+2 more22Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Function Cloud Native Environment+19 moreJun 17, 2026 Jun 11, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set wa...Show more |
9Apple DebianFedoraproject+6 more22Clustered Data Ontap Communications Billing And Revenue ManagementCommunications Cloud Native Core Policy+19 moreJun 17, 2026 Dec 14, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherw...Show more |
5Debian FujitsuHaxx+2 more10Curl Debian LinuxM10 1 Firmware+7 moreJun 17, 2026 Dec 14, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used. |
4Debian HaxxSiemens+1 more5Curl Debian LinuxSimatic Tim 1531 Irc Firmware+2 moreJun 17, 2026 Dec 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s). |
Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions...Show more |