Skip to main content

Vendor archive

haxx CVEs

Beta · best-effort

200 CVEs tagged to vendor haxx33 Critical, 56 High, 93 Medium, 18 Low, 0 Unrated.

CVE-2021-22890

Published Apr 1, 2021

curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HT…

CVSS 3.7 · Low

CVE-2021-22876

Published Apr 1, 2021

curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libc…

CVSS 5.3 · Medium

CVE-2020-8177

Published Dec 14, 2020

curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used.

CVSS 7.8 · High

CVE-2016-4606

Published Feb 21, 2020

Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-5443

Published Jul 2, 2019

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as a…

CVSS 7.8 · High

CVE-2019-5436

Published May 28, 2019

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS 7.8 · High

CVE-2019-5435

Published May 28, 2019

An integer overflow in curl's URL API results in a buffer overflow in libcurl 7.62.0 to and including 7.64.1.

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 101-125 of 200 CVEsPage 5 of 8