Vulnerabilities > Haxx

DATE CVE VULNERABILITY TITLE RISK
2017-11-29 CVE-2017-8818 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Haxx Curl and Libcurl
curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact because too little memory is allocated for interfacing to an SSL library.
network
low complexity
haxx CWE-119
7.5
2017-11-29 CVE-2017-8817 Out-of-bounds Read vulnerability in multiple products
The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character.
network
low complexity
haxx debian CWE-125
7.5
2017-11-29 CVE-2017-8816 Integer Overflow or Wraparound vulnerability in multiple products
The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields.
network
low complexity
haxx debian CWE-190
7.5
2017-10-31 CVE-2017-1000257 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An IMAP FETCH response line indicates the size of the returned data, in number of bytes.
network
low complexity
haxx debian CWE-119
6.4
2017-10-06 CVE-2017-1000254 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Haxx Libcurl
libcurl may read outside of a heap allocated buffer when doing FTP.
network
low complexity
haxx CWE-119
7.5
2017-10-05 CVE-2017-1000101 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Haxx Curl
curl supports "globbing" of URLs, in which a user can pass a numerical range to have the tool iterate over those numbers to do a sequence of transfers.
network
haxx CWE-119
4.3
2017-10-05 CVE-2017-1000100 Information Exposure vulnerability in Haxx Libcurl
When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is truncated to fit within the buffer boundaries, but the buffer size is still wrongly updated to use the untruncated length.
network
haxx CWE-200
4.3
2017-10-05 CVE-2017-1000099 Information Exposure vulnerability in Haxx Libcurl 7.54.1
When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers.
network
haxx CWE-200
4.3
2017-06-14 CVE-2017-9502 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Haxx Curl
In curl before 7.54.1 on Windows and DOS, libcurl's default protocol function, which is the logic that allows an application to set which protocol libcurl should attempt to use when given a URL without a scheme part, had a flaw that could lead to it overwriting a heap based memory buffer with seven bytes.
network
low complexity
haxx CWE-119
5.0
2017-04-03 CVE-2017-7407 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Haxx Curl 7.53.1
The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read.
local
low complexity
haxx CWE-119
2.1