Search: "curl"

302 CVEs found

Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows re...

Published: 2013-03-08
Products: 9
Vendors:
canonical haxx

lib/curl.rb in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

Published: 2013-03-20
Products: 1
Vendors:
curl_project
CVE-2013-1944
5.0 MEDIUM

The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix ...

Published: 2013-04-29
Products: 131
Vendors:
canonical haxx
CVE-2013-2174
6.8 MEDIUM

Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibl...

Published: 2013-07-31
Products: 169
Vendors:
canonical redhat haxx opensuse
CVE-2012-6087
5.8 MEDIUM

repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in...

Published: 2013-09-16
Products: 29
Vendors:
moodle
CVE-2013-4545
4.3 MEDIUM

cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_S...

Published: 2013-11-23
Products: 68
Vendors:
haxx
CVE-2013-6422
4.0 MEDIUM

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fiel...

Published: 2013-12-23
Products: 23
Vendors:
canonical debian haxx

The paratrooper-pingdom gem 1.0.0 for Ruby allows local users to obtain the App-Key, username, and password values by listing the curl process.

Published: 2014-01-10
Products: 1
Vendors:
tobias_maier

The paratrooper-newrelic gem 1.0.1 for Ruby allows local users to obtain the X-Api-Key value by listing the curl process.

Published: 2014-01-10
Products: 1
Vendors:
paratrooper-newrelic_project
CVE-2012-6086
4.3 MEDIUM

libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl, which allows man-in-the-m...

Published: 2014-01-29
Products: 22
Vendors:
zabbix
CVE-2014-0015
4.0 MEDIUM

cURL and libcurl 7.10.6 through 7.34.0, when more than one authentication method is enabled, re-uses NTLM connections, which might allow context-dependent attackers to authenticate as other users via ...

Published: 2014-02-02
Products: 128
Vendors:
haxx
CVE-2014-1263
4.3 MEDIUM

curl and libcurl 7.27.0 through 7.35.0, when using the SecureTransport/Darwinssl backend, as used in in Apple OS X 10.9.x before 10.9.2, does not verify that the server hostname matches a domain name ...

Published: 2014-02-27
Products: 2
Vendors:
apple
CVE-2014-0138
6.4 MEDIUM

The default configuration in cURL and libcurl 7.10.6 before 7.36.0 re-uses (1) SCP, (2) SFTP, (3) POP3, (4) POP3S, (5) IMAP, (6) IMAPS, (7) SMTP, (8) SMTPS, (9) LDAP, and (10) LDAPS connections, which...

Published: 2014-04-15
Products: 131
Vendors:
haxx debian
CVE-2014-0139
5.8 MEDIUM

cURL and libcurl 7.1 before 7.36.0, when using the OpenSSL, axtls, qsossl or gskit libraries for TLS, recognize a wildcard IP address in the subject's Common Name (CN) field of an X.509 certificate, w...

Published: 2014-04-15
Products: 130
Vendors:
haxx
CVE-2014-2522
4.0 MEDIUM

curl and libcurl 7.27.0 through 7.35.0, when running on Windows and using the SChannel/Winssl TLS backend, does not verify that the server hostname matches a domain name in the subject's Common Name (...

Published: 2014-04-18
Products: 22
Vendors:
haxx microsoft
CVE-2014-2576
6.8 MEDIUM

plugins/rssyl/feed.c in Claws Mail before 3.10.0 disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-i...

Published: 2014-10-15
Products: 3
Vendors:
claws-mail opensuse
CVE-2014-3707
4.3 MEDIUM

The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-...

Published: 2014-11-15
Products: 57
Vendors:
oracle haxx canonical apple debian +1 more
CVE-2014-3613
5.0 MEDIUM

cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrate...

Published: 2014-11-18
Products: 17
Vendors:
apple haxx
CVE-2014-3620
5.0 MEDIUM

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

Published: 2014-11-18
Products: 17
Vendors:
apple haxx
CVE-2015-3143
5.0 MEDIUM

cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-00...

Published: 2015-04-24
Products: 155
Vendors:
haxx canonical hp apple debian