curl kayıtları
curl üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %85,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-310 Cryptographic Issues1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2012-0036İstismar yok | curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remcurl · curl · CWE-89 | Yüksek7,5 | — | %16,1 | 13 Nis 2012 |
32İzleyin | CVE-2005-3185İstismar yok | Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and othercurl · curl · CWE-119 | Yüksek7,5 | — | %5,2 | 13 Eki 2005 |
31İzleyin | CVE-2009-2417İstismar yok | lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in thecurl · libcurl · CWE-310 | Yüksek7,5 | — | %3,5 | 14 Ağu 2009 |
30İzleyin | CVE-2009-0037Kavram kanıtı | The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location valucurl · curl · CWE-352 | Orta6,8 | — | %9,1 | 4 Mar 2009 |
28İzleyin | CVE-2010-0734İstismar yok | content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to ancurl · libcurl · CWE-264 | Orta6,8 | — | %3,6 | 19 Mar 2010 |
24İzleyin | CVE-2010-3842İstismar yok | Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote servecurl · curl · CWE-22 | Orta5,8 | — | %1,7 | 27 Eki 2010 |
18İzleyin | CVE-2025-11563İstismar yok | wcurl path traversal with percent-encoded slashescurl · wcurl · CWE-22 | Orta4,6 | — | %0,4 | 25 Şub 2026 |
- CVE-2012-003635İzleyin
curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows rem
YüksekCVSS 7,5İstismar yokEPSS %16curl · curl13 Nis 2012
- CVE-2005-318532İzleyin
Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other
YüksekCVSS 7,5İstismar yokEPSS %5curl · curl13 Eki 2005
- CVE-2009-241731İzleyin
lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the
YüksekCVSS 7,5İstismar yokEPSS %3curl · libcurl14 Ağu 2009
- CVE-2009-003730İzleyin
The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location valu
OrtaCVSS 6,8Kavram kanıtıEPSS %9curl · curl4 Mar 2009
- CVE-2010-073428İzleyin
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an
OrtaCVSS 6,8İstismar yokEPSS %4curl · libcurl19 Mar 2010
- CVE-2010-384224İzleyin
Absolute path traversal vulnerability in curl 7.20.0 through 7.21.1, when the --remote-header-name or -J option is used, allows remote serve
OrtaCVSS 5,8İstismar yokEPSS %2curl · curl27 Eki 2010
- CVE-2025-1156318İzleyin
wcurl path traversal with percent-encoded slashes
OrtaCVSS 4,6İstismar yokEPSS %0curl · wcurl25 Şub 2026