Where
-Infinity
0
Severity
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The verifycertificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, allows remote attackers to obtain sensitive information, cause a denial of service (crash), or possibly have unspecified other impact via a wildcard certificate name, which triggers an out-of-bounds read.

First published (updated )
Severity
8.1
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

The verifycertificate function in lib/vtls/schannel.c in libcurl 7.30.0 through 7.51.0, when built for Windows CE using the schannel TLS backend, makes it easier for remote attackers to conduct man-in-the-middle attacks via a crafted wildcard SAN in a server certificate, as demonstrated by ".com."

First published (updated )
Severity
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation of Privilege Vulnerability".

First published (updated )
EOL
Jul 11, 2023
Support Ends
Jul 10, 2018

End of life: 7/11/2023, End of support: 7/10/2018

First published (updated )
EOL
Jul 11, 2023
Support Ends
Jul 10, 2018

End of life: 7/11/2023, End of support: 7/10/2018

EOL
Jul 11, 2023
Support Ends
Jul 10, 2018

End of life: 7/11/2023, End of support: 7/10/2018

First published (updated )
EOL
Jan 10, 2023
Support Ends
Jan 9, 2018

End of life: 1/10/2023, End of support: 1/9/2018

First published (updated )
EOL
Oct 10, 2023
Support Ends
Oct 9, 2018

End of life: 10/10/2023, End of support: 10/9/2018

First published (updated )
EOL
Oct 10, 2023
Support Ends
Oct 9, 2018

End of life: 10/10/2023, End of support: 10/9/2018

EOL
Oct 10, 2023
Support Ends
Oct 9, 2018

End of life: 10/10/2023, End of support: 10/9/2018

First published (updated )
EOL
Oct 12, 2021
Support Ends
Oct 11, 2016

End of life: 10/12/2021, End of support: 10/11/2016

First published (updated )
EOL
Apr 13, 2021
Support Ends
Apr 12, 2016

End of life: 4/13/2021, End of support: 4/12/2016

First published (updated )
EOL
Apr 13, 2021
Support Ends
Apr 12, 2016

End of life: 4/13/2021, End of support: 4/12/2016

EOL
Apr 13, 2021
Support Ends
Apr 12, 2016

End of life: 4/13/2021, End of support: 4/12/2016

First published (updated )
EOL
Oct 13, 2020
Support Ends
Oct 13, 2015

End of life: 10/13/2020, End of support: 10/13/2015

First published (updated )
Severity
9.3
Code Injection
AV:N/AC:M/Au:N/C:C/I:C/A:C

Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted (1) JPEG and (2) GIF images.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203