Haxx
Haxx Libcurl: vulnerabilidades y CVE
Haxx Libcurl tiene 61 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 11 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE61
Últimos 12 meses0
Críticas11
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-0725 | Alta (7.3) | 1.3% | — | 5 feb 2025 | When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would… |
| CVE-2024-32928 | Media (5.9) | 0.19% | — | 19 ago 2024 | The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the… |
| CVE-2024-7264 | Media (6.5) | 17% | — | 31 jul 2024 | libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time… |
| CVE-2024-6874 | Media (4.3) | 0.79% | — | 24 jul 2024 | libcurl's URL API function [curl_url_get()](https://curl.se/libcurl/c/curl_url_get.html) offers punycode conversions, to and from IDN. Asking to convert a name that is exactly 256 bytes, libcurl ends up reading outside… |
| CVE-2024-6197 | Alta (7.5) | 4.3% | — | 24 jul 2024 | libcurl's ASN1 parser has this utf8asn1str() function used for parsing an ASN.1 UTF-8 string. Itcan detect an invalid field and return error. Unfortunately, when doing so it also invokes `free()` on a 4 byte localstack… |
| CVE-2023-38546 | Baja (3.7) | 6.2% | — | 18 oct 2023 | This flaw allows an attacker to insert cookies at will into a running program using libcurl, if the specific series of conditions are met. libcurl performs transfers. In its API, an application creates "easy handles"… |
| CVE-2023-38545 | Crítica (9.8) | 78% | — | 18 oct 2023 | This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl… |
| CVE-2023-27538 | Media (5.5) | 1.3% | — | 30 mar 2023 | An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse.… |
| CVE-2023-27537 | Media (5.9) | 1.9% | — | 30 mar 2023 | A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no… |
| CVE-2023-27536 | Media (5.9) | 1.6% | — | 30 mar 2023 | An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in… |
| CVE-2023-27535 | Media (5.9) | 1.6% | — | 30 mar 2023 | An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in… |
| CVE-2021-22945 | Crítica (9.1) | 6.7% | — | 23 sept 2021 | When sending data to an MQTT server, libcurl <= 7.73.0 and 7.78.0 could in some circumstances erroneously keep a pointer to an already freed memory area and both use that again in a subsequent call to send data and also… |
| CVE-2021-22924 | Baja (3.7) | 6.3% | — | 5 ago 2021 | libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into… |
| CVE-2021-22890 | Baja (3.7) | 3.1% | — | 1 abr 2021 | curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can… |
| CVE-2021-22876 | Media (5.3) | 5.3% | — | 1 abr 2021 | curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials… |
| CVE-2020-8286 | Alta (7.5) | 4.6% | — | 14 dic 2020 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. |
| CVE-2020-8285 | Alta (7.5) | 9.8% | — | 14 dic 2020 | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. |
| CVE-2020-8231 | Alta (7.5) | 3.8% | — | 14 dic 2020 | Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. |
| CVE-2019-5436 | Alta (7.8) | 50% | — | 28 may 2019 | A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. |
| CVE-2019-3823 | Alta (7.5) | 4.3% | — | 6 feb 2019 | libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains… |
| CVE-2019-3822 | Crítica (9.8) | 13% | — | 6 feb 2019 | libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates… |
| CVE-2018-16890 | Alta (7.5) | 5.4% | — | 6 feb 2019 | libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate… |
| CVE-2018-14618 | Crítica (9.8) | 11% | — | 5 sept 2018 | curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large… |
| CVE-2016-8622 | Crítica (9.8) | 4.7% | — | 31 jul 2018 | The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return… |
| CVE-2017-7468 | Alta (7.5) | 1.7% | — | 16 jul 2018 | In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is unacceptable since a server by specification is allowed to skip the… |
| CVE-2018-1000005 | Crítica (9.1) | 4.6% | — | 24 ene 2018 | libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers… |
| CVE-2017-8818 | Crítica (9.8) | 3.8% | — | 29 nov 2017 | curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact because too little memory is… |
| CVE-2017-8817 | Crítica (9.8) | 11% | — | 29 nov 2017 | The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that… |
| CVE-2017-8816 | Crítica (9.8) | 8.5% | — | 29 nov 2017 | The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly… |
| CVE-2017-1000257 | Crítica (9.1) | 6.2% | — | 31 oct 2017 | An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero)… |