CVEs (61)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Netapp SplunkSqlite3Ontap Select Deploy Administration Utility SqliteUniversal ForwarderJun 17, 2026 Aug 3, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API. |
6Apple DebianFedoraproject+3 more14Bootstrap Os Clustered Data OntapCurl+11 moreJun 17, 2026 Jul 7, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the...Show more |
6Apple DebianFedoraproject+3 more14Bootstrap Os Clustered Data OntapCurl+11 moreJun 17, 2026 Jul 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation...Show more |
6Debian FedoraprojectHaxx+3 more19Bootstrap Os Clustered Data OntapCurl+16 moreJun 17, 2026 Jul 7, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompress...Show more |
7Apple DebianFedoraproject+4 more19Clustered Data Ontap CurlDebian Linux+16 moreJun 17, 2026 Jul 7, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this,...Show more |
1Splunk 2Splunk Universal ForwarderJun 17, 2026 Jun 15, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 In Splunk Enterprise and Universal Forwarder versions before 9.0, the Splunk command-line interface (CLI) did not validate TLS certificates while connecting to a remote Splunk platform instance by default. After updating...Show more |
3Haxx NetappSplunk10Clustered Data Ontap CurlH300s Firmware+7 moreJun 17, 2026 Jun 2, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be bypassed if the host name in the given U...Show more |
3Debian HaxxSplunk3Curl Debian LinuxUniversal ForwarderJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttra...Show more |
4Debian HaxxNetapp+1 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl provides the `CURLOPT_CERTINFO` option to allow applications torequest details to be returned about a server's certificate chain.Due to an erroneous function, a malicious server could make libcurl built withNSS g...Show more |
3Haxx NetappSplunk10Clustered Data Ontap CurlH300s Firmware+7 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it is later retrieved.For example, a URL lik...Show more |
3Haxx NetappSplunk11Clustered Data Ontap CurlH300s Firmware+8 moreJun 17, 2026 Jun 2, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie engine" can bebuilt with or without [Publ...Show more |
4Haxx NetappOracle+1 more14Active Iq Unified Manager Bh500s FirmwareClustered Data Ontap+11 moreJun 17, 2026 Jun 2, 2022 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`. |
6Brocade DebianFedoraproject+3 more13Clustered Data Ontap CurlDebian Linux+10 moreJun 17, 2026 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. |
5Brocade DebianHaxx+2 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id it could reuse a connection instead. |
5Brocade DebianHaxx+2 more12Clustered Data Ontap CurlDebian Linux+9 moreJun 17, 2026 Jun 2, 2022 N/A· v4 5.7 MEDIUM· v3 3.5 LOW· v2 An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authenticat...Show more |
5Brocade DebianHaxx+2 more12Bootstrap Os Clustered Data OntapCurl+9 moreJun 17, 2026 May 26, 2022 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the...Show more |
8Apple DebianFedoraproject+5 more26Cloud Backup Clustered Data OntapCommerce Guided Search+23 moreJun 17, 2026 Sep 29, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl woul...Show more |
8Apple DebianFedoraproject+5 more29Cloud Backup Clustered Data OntapCommerce Guided Search+26 moreJun 17, 2026 Sep 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLU...Show more |
8Apple DebianFedoraproject+5 more17Cloud Backup Clustered Data OntapDebian Linux+14 moreJun 17, 2026 Sep 23, 2021 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also...Show more |
5Haxx NetappOracle+2 more19Active Iq Unified Manager Clustered Data OntapCurl+16 moreJun 17, 2026 Aug 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS n...Show more |