Логотип exploitDog
product: "mysql_server"
Консоль
Логотип exploitDog

exploitDog

product: "mysql_server"

Количество 1 198

Количество 1 198

nvd логотип

CVE-2021-22922

около 4 лет назад

When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several of them. In a serial orparallel manner.If one of the servers hosting the contents has been breached and the contentsof the specific file on that server is replaced with a modified payload, curlshould detect this when the hash of the file mismatches after a completeddownload. It should remove the contents and instead try getting the contentsfrom another URL. This is not done, and instead such a hash mismatch is onlymentioned in text and the potentially malicious content is kept in the file ondisk.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-22922

около 4 лет назад

When curl is instructed to download content using the metalink feature ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-5481

около 6 лет назад

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2019-5481

около 6 лет назад

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2019-5481

около 6 лет назад

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-5481

около 6 лет назад

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7 ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-5436

больше 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2019-5436

больше 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2019-5436

больше 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2019-5436

больше 6 лет назад

A heap buffer overflow in the TFTP receiving code allows for DoS or ar ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-rh8g-j53h-g8xf

больше 3 лет назад

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-79v3-h2vf-vcg6

больше 3 лет назад

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2022-27778

больше 3 лет назад

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2022-27778

больше 3 лет назад

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2022-27778

больше 3 лет назад

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2022-27778

больше 3 лет назад

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2019-5443

больше 6 лет назад

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2019-5443

больше 6 лет назад

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2019-5443

больше 6 лет назад

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2019-5443

больше 6 лет назад

A non-privileged user or program can put code and a config file in a k ...

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-22922

When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several of them. In a serial orparallel manner.If one of the servers hosting the contents has been breached and the contentsof the specific file on that server is replaced with a modified payload, curlshould detect this when the hash of the file mismatches after a completeddownload. It should remove the contents and instead try getting the contentsfrom another URL. This is not done, and instead such a hash mismatch is onlymentioned in text and the potentially malicious content is kept in the file ondisk.

CVSS3: 6.5
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-22922

When curl is instructed to download content using the metalink feature ...

CVSS3: 6.5
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2019-5481

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

CVSS3: 9.8
2%
Низкий
около 6 лет назад
redhat логотип
CVE-2019-5481

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

CVSS3: 5.7
2%
Низкий
около 6 лет назад
nvd логотип
CVE-2019-5481

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.

CVSS3: 9.8
2%
Низкий
около 6 лет назад
debian логотип
CVE-2019-5481

Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7 ...

CVSS3: 9.8
2%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2019-5436

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7.8
3%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-5436

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-5436

A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.

CVSS3: 7.8
3%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-5436

A heap buffer overflow in the TFTP receiving code allows for DoS or ar ...

CVSS3: 7.8
3%
Низкий
больше 6 лет назад
github логотип
GHSA-rh8g-j53h-g8xf

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-79v3-h2vf-vcg6

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-27778

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-27778

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-27778

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might remove the wrong file when `--no-clobber` is used together with `--remove-on-error`.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-27778

A use of incorrectly resolved name vulnerability fixed in 7.83.1 might ...

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2019-5443

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
0%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-5443

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 8.4
0%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-5443

A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything it wants.

CVSS3: 7.8
0%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-5443

A non-privileged user or program can put code and a config file in a k ...

CVSS3: 7.8
0%
Низкий
больше 6 лет назад

Уязвимостей на страницу