curl records
7 published records for vendor curl.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 85.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-310 Cryptographic Issues1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2012-0036No exploit | curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remcurl · curl · CWE-89 | High7.5 | — | 16.1% | Apr 13, 2012 |
32Monitor | CVE-2005-3185No exploit | Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and othercurl · curl · CWE-119 | High7.5 | — | 5.2% | Oct 13, 2005 |
31Monitor | CVE-2009-2417No exploit | lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in thecurl · libcurl · CWE-310 | High7.5 | — | 3.5% | Aug 14, 2009 |
30Monitor | CVE-2009-0037Proof of concept | The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location valucurl · curl · CWE-352 | Medium6.8 | — | 9.1% | Mar 4, 2009 |
28Monitor | CVE-2010-0734No exploit | content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to ancurl · libcurl · CWE-264 | Medium6.8 | — | 3.6% | Mar 19, 2010 |
24Monitor | CVE-2010-3842No exploit | Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servecurl · curl · CWE-22 | Medium5.8 | — | 1.7% | Oct 27, 2010 |
18Monitor | CVE-2025-11563No exploit | wcurl path traversal with percent-encoded slashescurl · wcurl · CWE-22 | Medium4.6 | — | 0.4% | Feb 25, 2026 |
- CVE-2012-003635Monitor
curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows rem
HighCVSS 7.5No exploitEPSS 16%curl · curlApr 13, 2012
- CVE-2005-318532Monitor
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other
HighCVSS 7.5No exploitEPSS 5%curl · curlOct 13, 2005
- CVE-2009-241731Monitor
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the
HighCVSS 7.5No exploitEPSS 3%curl · libcurlAug 14, 2009
- CVE-2009-003730Monitor
The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location valu
MediumCVSS 6.8Proof of conceptEPSS 9%curl · curlMar 4, 2009
- CVE-2010-073428Monitor
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an
MediumCVSS 6.8No exploitEPSS 4%curl · libcurlMar 19, 2010
- CVE-2010-384224Monitor
Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote serve
MediumCVSS 5.8No exploitEPSS 2%curl · curlOct 27, 2010
- CVE-2025-1156318Monitor
wcurl path traversal with percent-encoded slashes
MediumCVSS 4.6No exploitEPSS 0%curl · wcurlFeb 25, 2026