libcurl records
3 published records for vendor libcurl.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-310 Cryptographic Issues1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2005-3185No exploit | Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and othercurl · curl · CWE-119 | High7.5 | — | 5.2% | Oct 13, 2005 |
31Monitor | CVE-2009-2417No exploit | lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in thecurl · libcurl · CWE-310 | High7.5 | — | 3.5% | Aug 14, 2009 |
31Monitor | CVE-2007-3564No exploit | libcurl 7.14.0 through 7.16.3, when built with GnuTLS support, does not check SSL/TLS certificate expiration or activation dates, which allolibcurl · libcurl | High7.5 | — | 2.3% | Jul 18, 2007 |
- CVE-2005-318532Monitor
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other
HighCVSS 7.5No exploitEPSS 5%curl · curlOct 13, 2005
- CVE-2009-241731Monitor
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the
HighCVSS 7.5No exploitEPSS 3%curl · libcurlAug 14, 2009
- CVE-2007-356431Monitor
libcurl 7.14.0 through 7.16.3, when built with GnuTLS support, does not check SSL/TLS certificate expiration or activation dates, which allo
HighCVSS 7.5No exploitEPSS 2%libcurl · libcurlJul 18, 2007