Логотип exploitDog
bind:"BDU:2023-02105" OR bind:"CVE-2023-27537"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2023-02105" OR bind:"CVE-2023-27537"

Количество 8

Количество 8

fstec логотип

BDU:2023-02105

почти 3 года назад

Уязвимость библиотеки libcurl, связанная с отсутствием мьютексов или блокировок потоков, позволяющая нарушителю использовать память после освобождения

CVSS3: 5.6
EPSS: Низкий
redos логотип

ROS-20230407-01

почти 3 года назад

Множественные уязвимости libcurl

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2023-27537

почти 3 года назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2023-27537

почти 3 года назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2023-27537

почти 3 года назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2023-27537

почти 3 года назад

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-27537

почти 3 года назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-9j2c-vm53-wcvm

почти 3 года назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-02105

Уязвимость библиотеки libcurl, связанная с отсутствием мьютексов или блокировок потоков, позволяющая нарушителю использовать память после освобождения

CVSS3: 5.6
0%
Низкий
почти 3 года назад
redos логотип
ROS-20230407-01

Множественные уязвимости libcurl

CVSS3: 5.9
почти 3 года назад
ubuntu логотип
CVE-2023-27537

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-27537

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.6
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-27537

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 5.9
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-27537

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS ...

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-9j2c-vm53-wcvm

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
0%
Низкий
почти 3 года назад

Уязвимостей на страницу