Haxx
haxx
181 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (181)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
curl before version 7.51.0 doesn't parse the authority component of the URL correctly when the host name part ends with a '#' character, and could instead be tricked into connecting to a different host. This may have sec...Show more |
The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return...Show more |
The libcurl API function called `curl_maprintf()` before version 7.51.0 can be tricked into doing a double-free due to an unsafe `size_t` multiplication, on systems using 32 bit `size_t` variables. |
curl before 7.53.0 has an incorrect TLS Certificate Status Request extension feature that asks for a fresh proof of the server's certificate's validity in the code that checks for a test success or failure. It ends up al...Show more |
In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is unacceptable since a server by specification is allowed to skip the cl...Show more |
2Canonical Haxx2Curl Ubuntu LinuxNov 21, 2024 Jul 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and including curl 7.60.0 has a heap-based buffer overflow that might be exploitable by an attacker who can control the data that curl transmits over SMTP with certain...Show more |
5Canonical DebianHaxx+2 more9Communications Webrtc Session Controller CurlDebian Linux+6 moreApr 15, 2026 May 24, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer...Show more |
2Canonical Haxx2Curl Ubuntu LinuxNov 21, 2024 May 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 curl version curl 7.54.1 to and including curl 7.59.0 contains a CWE-122: Heap-based Buffer Overflow vulnerability in denial of service and more that can result in curl might overflow a heap based memory buffer when clos...Show more |
curl before version 7.52.1 is vulnerable to an uninitialized random in libcurl's internal function that returns a good 32bit random value. Having a weak or virtually non-existent random value makes the operations that u...Show more |
curl before version 7.52.0 is vulnerable to a buffer overflow when doing a large floating point output in libcurl's implementation of the printf() functions. If there are any application that accepts a format string from...Show more |
5Canonical DebianHaxx+2 more9Communications Webrtc Session Controller CurlDebian Linux+6 moreNov 21, 2024 Mar 14, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage |
5Canonical DebianHaxx+2 more9Communications Webrtc Session Controller CurlDebian Linux+6 moreNov 21, 2024 Mar 14, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A NULL pointer dereference exists in curl 7.21.0 to and including curl 7.58.0 in the LDAP code that allows an attacker to cause a denial of service |
5Canonical DebianHaxx+2 more9Communications Webrtc Session Controller CurlDebian Linux+6 moreNov 21, 2024 Mar 14, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or worse. |
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial o...Show more |
The verify_certificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, makes it easier for remote attackers to conduct man-in-the-middle attacks...Show more |
curl, as shipped in Red Hat Enterprise Linux 6 before version 7.19.7-53, did not correctly backport the fix for CVE-2015-3148 because it did not reflect the fact that the HAVE_GSSAPI define was meanwhile substituted by U...Show more |
5Canonical DebianFujitsu+2 more14Curl Debian LinuxEnterprise Linux Desktop+11 moreNov 21, 2024 Jan 24, 2018 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL...Show more |
3Canonical DebianHaxx3Debian Linux LibcurlUbuntu LinuxNov 21, 2024 Jan 24, 2018 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers s...Show more |
curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact because too little memory is allocate...Show more |
2Debian Haxx3Curl Debian LinuxLibcurlMay 13, 2026 Nov 29, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends...Show more |