Логотип exploitDog
bind:"BDU:2023-02105" OR bind:"CVE-2023-27537"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2023-02105" OR bind:"CVE-2023-27537"

Количество 8

Количество 8

fstec логотип

BDU:2023-02105

больше 2 лет назад

Уязвимость библиотеки libcurl, связанная с отсутствием мьютексов или блокировок потоков, позволяющая нарушителю использовать память после освобождения

CVSS3: 5.6
EPSS: Низкий
ubuntu логотип

CVE-2023-27537

больше 2 лет назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2023-27537

больше 2 лет назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2023-27537

больше 2 лет назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
EPSS: Низкий
msrc логотип

CVE-2023-27537

больше 2 лет назад

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-27537

больше 2 лет назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-9j2c-vm53-wcvm

больше 2 лет назад

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
EPSS: Низкий
redos логотип

ROS-20230407-01

больше 2 лет назад

Множественные уязвимости libcurl

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-02105

Уязвимость библиотеки libcurl, связанная с отсутствием мьютексов или блокировок потоков, позволяющая нарушителю использовать память после освобождения

CVSS3: 5.6
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-27537

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2023-27537

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.6
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-27537

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 5.9
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-27537

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS ...

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-9j2c-vm53-wcvm

A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks, two threads sharing the same HSTS data could end up doing a double-free or use-after-free.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
redos логотип
ROS-20230407-01

Множественные уязвимости libcurl

CVSS3: 5.9
больше 2 лет назад

Уязвимостей на страницу