Логотип exploitDog
bind:"CVE-2022-43552" OR bind:"CVE-2022-35252"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-43552" OR bind:"CVE-2022-35252"

Количество 31

Количество 31

oracle-oval логотип

ELSA-2023-2963

больше 2 лет назад

ELSA-2023-2963: curl security and bug fix update (LOW)

EPSS: Низкий
oracle-oval логотип

ELSA-2023-2478

больше 2 лет назад

ELSA-2023-2478: curl security update (LOW)

EPSS: Низкий
ubuntu логотип

CVE-2022-35252

больше 3 лет назад

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2022-35252

больше 3 лет назад

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2022-35252

больше 3 лет назад

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.7
EPSS: Низкий
msrc логотип

CVE-2022-35252

больше 3 лет назад

When curl is used to retrieve and parse cookies from a HTTP(S) server itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2022-35252

больше 3 лет назад

When curl is used to retrieve and parse cookies from a HTTP(S) server, ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2022-43552

почти 3 года назад

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2022-43552

около 3 лет назад

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2022-43552

почти 3 года назад

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2022-43552

почти 3 года назад

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET curl would use a heap-allocated struct after it had been freed in its transfer shutdown code path.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2022-43552

почти 3 года назад

A use after free vulnerability exists in curl <7.87.0. Curl can be ask ...

CVSS3: 5.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3005-1

больше 3 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3004-1

больше 3 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3003-1

больше 3 лет назад

Security update for curl

EPSS: Низкий
github логотип

GHSA-qc3c-r429-gpgf

больше 3 лет назад

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.7
EPSS: Низкий
fstec логотип

BDU:2022-06193

больше 3 лет назад

Уязвимость утилиты командной строки cURL, связанная с недостаточной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4633-1

около 3 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:4598-1

около 3 лет назад

Security update for curl

EPSS: Низкий
github логотип

GHSA-6342-4x32-pp8v

почти 3 года назад

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2023-2963

ELSA-2023-2963: curl security and bug fix update (LOW)

больше 2 лет назад
oracle-oval логотип
ELSA-2023-2478

ELSA-2023-2478: curl security update (LOW)

больше 2 лет назад
ubuntu логотип
CVE-2022-35252

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-35252

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.1
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-35252

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-35252

When curl is used to retrieve and parse cookies from a HTTP(S) server itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-35252

When curl is used to retrieve and parse cookies from a HTTP(S) server, ...

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-43552

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-43552

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

CVSS3: 5.9
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-43552

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
msrc логотип
CVE-2022-43552

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET curl would use a heap-allocated struct after it had been freed in its transfer shutdown code path.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-43552

A use after free vulnerability exists in curl <7.87.0. Curl can be ask ...

CVSS3: 5.9
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3005-1

Security update for curl

0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3004-1

Security update for curl

0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3003-1

Security update for curl

0%
Низкий
больше 3 лет назад
github логотип
GHSA-qc3c-r429-gpgf

When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings.

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-06193

Уязвимость утилиты командной строки cURL, связанная с недостаточной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 3.7
0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:4633-1

Security update for curl

0%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:4598-1

Security update for curl

0%
Низкий
около 3 лет назад
github логотип
GHSA-6342-4x32-pp8v

A use after free vulnerability exists in curl <7.87.0. Curl can be asked to *tunnel* virtually all protocols it supports through an HTTP proxy. HTTP proxies can (and often do) deny such tunnel operations. When getting denied to tunnel the specific protocols SMB or TELNET, curl would use a heap-allocated struct after it had been freed, in its transfer shutdown code path.

CVSS3: 7.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу