Filter
AND

ubuntu/curlCurl and libcurl CVE-2023-38545 and CVE-2023-38546 vulnerabilities

3.7
First published (updated )

IBM Cognos AnalyticsASN.1 date parser overread

EPSS
0.06%
First published (updated )

Microsoft Windows 11freeing stack buffer in utf8asn1str

8.8
EPSS
0.04%
First published (updated )

Canonical Ubuntu LinuxLast updated 24 July 2024

7.5
First published (updated )

Canonical Ubuntu LinuxBuffer Overflow

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Canonical Ubuntu LinuxInteger Overflow

7.5
First published (updated )

Apple Mac OS Xcurl. This issue was addressed with improved checks.

7.5
First published (updated )

Microsoft Windows 10Curl and libcurl CVE-2023-38545 and CVE-2023-38546 vulnerabilities

EPSS
0.18%
First published (updated )

Fedoraproject FedoraA flaw was found in the way libcurl handled TLS 1.3 session tickets. A malicious HTTPS proxy could p…

First published (updated )

Apple Mac OS XBuffer Overflow, Input Validation

7.5
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Haxx Libcurlmacidn punycode buffer overread

EPSS
0.04%
First published (updated )

redhat/curlcurl and libcurl before 7.50.1 do not prevent TLS session resumption when the client certificate has…

7.5
First published (updated )

redhat/curlcurl and libcurl before 7.50.1 do not check the client certificate when choosing the TLS connection …

7.5
First published (updated )

Canonical Ubuntu LinuxUse After Free

8.1
First published (updated )

Google Nest Mini FirmwareThe libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest producti…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Curl CurlBuffer Overflow

8.8
First published (updated )

Canonical Ubuntu LinuxThe Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in c…

First published (updated )

Haxx LibcurlInput Validation

First published (updated )

Haxx CurlcURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN…

First published (updated )

Haxx CurlBuffer Overflow

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Haxx CurlInfoleak

First published (updated )

Haxx CurlBuffer Overflow

7.5
First published (updated )

Haxx LibcurlThe darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, …

First published (updated )

Haxx LibcurlCRLF Injection

First published (updated )

Haxx LibcurlInfoleak

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Haxx CurlcURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which a…

First published (updated )

Haxx CurlcURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cooki…

First published (updated )

Haxx LibcurlInput Validation

First published (updated )

Haxx CurlThe default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) PO…

First published (updated )

Haxx CurlcURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203