Skip to content
Noroxi

curl records

7 published records for vendor curl.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

7 records
  • CVE-2012-0036
    35Monitor

    curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows rem

    HighCVSS 7.5No exploitEPSS 16%

    curl · curlApr 13, 2012

  • CVE-2005-3185
    32Monitor

    Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other

    HighCVSS 7.5No exploitEPSS 5%

    curl · curlOct 13, 2005

  • CVE-2009-2417
    31Monitor

    lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the

    HighCVSS 7.5No exploitEPSS 3%

    curl · libcurlAug 14, 2009

  • CVE-2009-0037
    30Monitor

    The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location valu

    MediumCVSS 6.8Proof of conceptEPSS 9%

    curl · curlMar 4, 2009

  • CVE-2010-0734
    28Monitor

    content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an

    MediumCVSS 6.8No exploitEPSS 4%

    curl · libcurlMar 19, 2010

  • CVE-2010-3842
    24Monitor

    Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote serve

    MediumCVSS 5.8No exploitEPSS 2%

    curl · curlOct 27, 2010

  • wcurl path traversal with percent-encoded slashes

    MediumCVSS 4.6No exploitEPSS 0%

    curl · wcurlFeb 25, 2026