Количество 9
Количество 9

CVE-2023-38039
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

CVE-2023-38039
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

CVE-2023-38039
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

CVE-2023-38039
Hackerone: CVE-2023-38039 HTTP headers eat all memory
CVE-2023-38039
When curl retrieves an HTTP response, it stores the incoming headers s ...

SUSE-SU-2023:3823-1
Security update for curl

SUSE-SU-2023:3692-1
Security update for curl
GHSA-99j9-jf36-9747
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.

BDU:2023-05819
Уязвимость интерфейса утилиты командной строки cURL, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2023-38039 When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory. | CVSS3: 7.5 | 14% Средний | почти 2 года назад |
![]() | CVE-2023-38039 When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory. | CVSS3: 7.5 | 14% Средний | почти 2 года назад |
![]() | CVE-2023-38039 When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory. | CVSS3: 7.5 | 14% Средний | почти 2 года назад |
![]() | CVE-2023-38039 Hackerone: CVE-2023-38039 HTTP headers eat all memory | 14% Средний | больше 1 года назад | |
CVE-2023-38039 When curl retrieves an HTTP response, it stores the incoming headers s ... | CVSS3: 7.5 | 14% Средний | почти 2 года назад | |
![]() | SUSE-SU-2023:3823-1 Security update for curl | 14% Средний | больше 1 года назад | |
![]() | SUSE-SU-2023:3692-1 Security update for curl | 14% Средний | почти 2 года назад | |
GHSA-99j9-jf36-9747 When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory. | CVSS3: 7.5 | 14% Средний | почти 2 года назад | |
![]() | BDU:2023-05819 Уязвимость интерфейса утилиты командной строки cURL, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 8.8 | 14% Средний | почти 2 года назад |
Уязвимостей на страницу