Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-4802

Опубликовано: 24 июн. 2016
Источник: nvd
CVSS3: 7.8
CVSS2: 6.9
EPSS Низкий

Описание

Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) security.dll, (2) secur32.dll, or (3) ws2_32.dll in the application or current working directory.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*
Версия до 7.49.0 (включая)

EPSS

Процентиль: 69%
0.00612
Низкий

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) security.dll, (2) secur32.dll, or (3) ws2_32.dll in the application or current working directory.

CVSS3: 7.8
debian
больше 9 лет назад

Multiple untrusted search path vulnerabilities in cURL and libcurl bef ...

CVSS3: 7.8
github
больше 3 лет назад

Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) security.dll, (2) secur32.dll, or (3) ws2_32.dll in the application or current working directory.

EPSS

Процентиль: 69%
0.00612
Низкий

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-264