haxx curl
153 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
proxyA) with Digest authentication and then changing.netrc file for credentials and to follow HTTP redirects, libcurl could leak the password used for theHost: header is first set for an HTTP request and a second request is subsequently done using the s/ or \) can trick wcurl into saving the output file outside of the current directoryCURLSSLOPT_NO_PARTIALCHAIN option, libcurlCURLOPT_PINNEDPUBLICKEY option with libcurl or --pinnedpubkey with the curl tool,curl should check the public key osecure keyword for https://target 2. curl is redirected to or otherwise made to speak with `httCURLOPT_ACCEPT_ENCODING.netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the firs.netrc file for credentials and to follow HTTP redirects, curl could leak the password used for the fir.netrc file for credentials. If that file endsin a line with 4095 consecutive non-white space letterCURLOPT_READFUNCTION) to ask for data to send, evSet-Cookie: headers in a HTTP response to curl and curl < 7.84.0 stores all ofCURLOPT_CERTINFO option to allow applications torequest details to be returned about a server's certificate--no-clobber is used together-t command line option, known as CURLOPT_TELNETOPTIONSin libcurl. This rarely used option is used to send va-t command line option, known as CURLOPT_TELNETOPTIONSread_data() in security.c in curl before version 7.51.0 is vulnerable to memory double free.curl_getdate function in curl before version 7.51.0 is vulnerable to an out of bounds read if it receives an input with onecurl_maprintf() before version 7.51.0 can be tricked into doing a double-free due to an unsafe `