No coverage found in monitored research blogs or news feeds.
| CVE | CVSS | Affected |
|---|---|---|
| CVE-2023-23914 | 9.1 Critical | n/a https://github.com/curl/curl A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs a… |
| CVE-2023-38545 | 8.8 High | curl curl This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy … |
| CVE-2020-8285 | 7.5 High | n/a https://github.com/curl/curl curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. |
| CVE-2023-23915 | 6.5 Medium | n/a https://github.com/curl/curl A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly whe… |
| CVE-2018-1000120 | — | n/a n/a A buffer overflow exists in curl 7.12.3 to and including curl 7.58.0 in the FTP URL handling that allows an attacker to cause a denial of service or … |
| CVE-2018-1000122 | — | n/a n/a A buffer over-read exists in curl 7.20.0 to and including curl 7.58.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of serv… |
| CVE-2020-8286 | — | n/a https://github.com/curl/curl curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. |
Extracted from the publication text. Each CVE links to its tracked detail page.
Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.