Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2015-3237

Опубликовано: 22 июн. 2015
Источник: nvd
CVSS2: 6.4
EPSS Низкий

Описание

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:haxx:curl:7.40.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:curl:7.41.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:curl:7.42.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:curl:7.42.1:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.40.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.41.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.42.0:*:*:*:*:*:*:*
cpe:2.3:a:haxx:libcurl:7.42.1:*:*:*:*:*:*:*
Конфигурация 2
cpe:2.3:a:hp:system_management_homepage:*:*:*:*:*:*:*:*
Версия до 7.5.3.1 (включая)
Конфигурация 3

Одно из

cpe:2.3:a:oracle:enterprise_manager_ops_center:12.1.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.2.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_manager_ops_center:12.3.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:glassfish_server:3.1.2:*:*:*:*:*:*:*

EPSS

Процентиль: 90%
0.05127
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-20

Связанные уязвимости

ubuntu
больше 10 лет назад

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

redhat
больше 10 лет назад

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

debian
больше 10 лет назад

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42 ...

github
больше 3 лет назад

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

EPSS

Процентиль: 90%
0.05127
Низкий

6.4 Medium

CVSS2

Дефекты

CWE-20