Записи curl
7 опубликованных записей вендора curl.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 85,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-310 Cryptographic Issues1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2012-0036Эксплойта нет | curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remcurl · curl · CWE-89 | Высокая7,5 | — | 16,1 % | 13 апр. 2012 г. |
32Наблюдать | CVE-2005-3185Эксплойта нет | Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and othercurl · curl · CWE-119 | Высокая7,5 | — | 5,2 % | 13 окт. 2005 г. |
31Наблюдать | CVE-2009-2417Эксплойта нет | lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in thecurl · libcurl · CWE-310 | Высокая7,5 | — | 3,5 % | 14 авг. 2009 г. |
30Наблюдать | CVE-2009-0037Proof of concept | The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location valucurl · curl · CWE-352 | Средняя6,8 | — | 9,1 % | 4 мар. 2009 г. |
28Наблюдать | CVE-2010-0734Эксплойта нет | content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to ancurl · libcurl · CWE-264 | Средняя6,8 | — | 3,6 % | 19 мар. 2010 г. |
24Наблюдать | CVE-2010-3842Эксплойта нет | Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servecurl · curl · CWE-22 | Средняя5,8 | — | 1,7 % | 27 окт. 2010 г. |
18Наблюдать | CVE-2025-11563Эксплойта нет | wcurl path traversal with percent-encoded slashescurl · wcurl · CWE-22 | Средняя4,6 | — | 0,4 % | 25 февр. 2026 г. |
- CVE-2012-003635Наблюдать
curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows rem
ВысокаяCVSS 7,5Эксплойта нетEPSS 16 %curl · curl13 апр. 2012 г.
- CVE-2005-318532Наблюдать
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %curl · curl13 окт. 2005 г.
- CVE-2009-241731Наблюдать
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %curl · libcurl14 авг. 2009 г.
- CVE-2009-003730Наблюдать
The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location valu
СредняяCVSS 6,8Proof of conceptEPSS 9 %curl · curl4 мар. 2009 г.
- CVE-2010-073428Наблюдать
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an
СредняяCVSS 6,8Эксплойта нетEPSS 4 %curl · libcurl19 мар. 2010 г.
- CVE-2010-384224Наблюдать
Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote serve
СредняяCVSS 5,8Эксплойта нетEPSS 2 %curl · curl27 окт. 2010 г.
- CVE-2025-1156318Наблюдать
wcurl path traversal with percent-encoded slashes
СредняяCVSS 4,6Эксплойта нетEPSS 0 %curl · wcurl25 февр. 2026 г.