Логотип exploitDog
bind:"CVE-2022-27774" OR bind:"CVE-2022-27782" OR bind:"CVE-2022-22576" OR bind:"CVE-2022-27776"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-27774" OR bind:"CVE-2022-27782" OR bind:"CVE-2022-22576" OR bind:"CVE-2022-27776"

Количество 43

Количество 43

github логотип

GHSA-x38v-8q6p-w65c

больше 3 лет назад

libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-03185

больше 3 лет назад

Уязвимость реализации протоколов TLS и SSH утилиты командной строки cURL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1870-1

больше 3 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1805-1

больше 3 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:1733-1

больше 3 лет назад

Security update for curl

EPSS: Низкий
ubuntu логотип

CVE-2022-27776

больше 3 лет назад

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-27776

больше 3 лет назад

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-27776

больше 3 лет назад

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2022-27776

больше 3 лет назад

HackerOne: CVE-2022-27776 Insufficiently protected credentials vulnerability might leak authentication or cookie header data

EPSS: Низкий
debian логотип

CVE-2022-27776

больше 3 лет назад

A insufficiently protected credentials vulnerability in fixed in curl ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-22576

больше 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2022-22576

больше 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2022-22576

больше 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
EPSS: Низкий
msrc логотип

CVE-2022-22576

больше 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S) IMAP(S) POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2022-22576

больше 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and ...

CVSS3: 8.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2829-1

больше 3 лет назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2813-1

больше 3 лет назад

Security update for curl

EPSS: Низкий
github логотип

GHSA-hc85-wpv5-52wh

больше 3 лет назад

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2r69-696x-qxj9

больше 3 лет назад

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2022-03040

больше 3 лет назад

Уязвимость утилиты командной строки cURL, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-x38v-8q6p-w65c

libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-03185

Уязвимость реализации протоколов TLS и SSH утилиты командной строки cURL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1870-1

Security update for curl

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1805-1

Security update for curl

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:1733-1

Security update for curl

больше 3 лет назад
ubuntu логотип
CVE-2022-27776

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-27776

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-27776

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-27776

HackerOne: CVE-2022-27776 Insufficiently protected credentials vulnerability might leak authentication or cookie header data

1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-27776

A insufficiently protected credentials vulnerability in fixed in curl ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2022-22576

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2022-22576

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22576

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
msrc логотип
CVE-2022-22576

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S) IMAP(S) POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22576

An improper authentication vulnerability exists in curl 7.33.0 to and ...

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2829-1

Security update for curl

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2813-1

Security update for curl

больше 3 лет назад
github логотип
GHSA-hc85-wpv5-52wh

A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-2r69-696x-qxj9

An improper authentication vulnerability exists in curl 7.33.0 to and including 7.82.0 which might allow reuse OAUTH2-authenticated connections without properly making sure that the connection was authenticated with the same credentials as set for this transfer. This affects SASL-enabled protocols: SMPTP(S), IMAP(S), POP3(S) and LDAP(S) (openldap only).

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
fstec логотип
BDU:2022-03040

Уязвимость утилиты командной строки cURL, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 4.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу