Skip to main content

Vendor archive

haxx CVEs

Beta · best-effort

200 CVEs tagged to vendor haxx33 Critical, 56 High, 93 Medium, 18 Low, 0 Unrated.

CVE-2023-23915

Published Feb 23, 2023

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested…

CVSS 6.5 · Medium

CVE-2023-23914

Published Feb 23, 2023

A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using i…

CVSS 9.1 · Critical

CVE-2022-35260

Published Dec 5, 2022

curl can be told to parse a `.netrc` file for credentials. If that file endsin a line with 4095 consecutive non-white space letters and no newline, curlwould first read past the e…

CVSS 6.5 · Medium

CVE-2022-32221

Published Dec 5, 2022

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been…

CVSS 9.8 · Critical

CVE-2022-42915

Published Oct 29, 2022

curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNE…

CVSS 8.1 · High

CVE-2022-30115

Published Jun 2, 2022

Using its HSTS support, curl can be instructed to use HTTPS directly insteadof using an insecure clear-text HTTP step even when HTTP is provided in theURL. This mechanism could be…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2022-27780

Published Jun 2, 2022

The curl URL parser wrongly accepts percent-encoded URL separators like '/'when decoding the host name part of a URL, making it a *different* URL usingthe wrong host name when it…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2022-27779

Published Jun 2, 2022

libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided with a trailing dot.curl can be told to receive and send cookies. curl's "cookie…

CVSS 5.3 · Medium
Showing 76-100 of 200 CVEsPage 4 of 8