Known vulnerabilities in curl (Alpine package)

Software CPE: cpe:2.3:o:alpine:curl_alpine_package:*:*:*:*:*:alpine_linux:*:*
Total vulnerabilities: 68
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting curl (Alpine package) curl (Alpine package) is affected by 68 known vulnerabilities: 19 high, 26 medium, 23 low Critical High Medium Low

Vulnerabilities (68)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU51822 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2021-22890
CWE-300 Medium
No
No
7.76.0-r0 31.03.2021 SB2021033111
SB2021040104
SB2021040117
and 15 more
#VU51821 - Exposure of sensitive information to an unauthorized actor
CVE-2021-22876
CWE-200 Medium
No
No
7.76.0-r0 31.03.2021 SB2021033111
SB2021040104
SB2021040117
and 31 more
#VU48895 - Improper Check for Certificate Revocation
CVE-2020-8286
CWE-299 Medium
No
No
7.74.0-r0 09.12.2020 SB2020120902
SB2020120915
SB2020120929
and 30 more
#VU48894 - Uncontrolled Recursion
CVE-2020-8285
CWE-674 Low
No
No
7.74.0-r0 09.12.2020 SB2020120902
SB2020120915
SB2020120928
and 37 more
#VU48893 - Exposure of sensitive information to an unauthorized actor
CVE-2020-8284
CWE-200 Medium
No
No
7.74.0-r0 09.12.2020 SB2020120902
SB2020120915
SB2020120927
and 31 more
#VU45794 - Expired pointer dereference
CVE-2020-8231
CWE-825 Low
No
No
7.72.0-r0 20.08.2020 SB2020081916
SB2020082001
SB2020081920
and 29 more
#VU29292 - Exposure of sensitive information to an unauthorized actor
CVE-2020-8169
CWE-200 Medium
No
No
7.71.0-r0 25.06.2020 SB2020062513
SB2020062514
SB2020063017
and 14 more
#VU29290 - Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2020-8177
CWE-644 Low
No
No
7.71.0-r0 25.06.2020 SB2020062511
SB2020062514
SB2020063002
and 27 more
#VU18583 - Integer overflow
CVE-2019-5435
CWE-190 Medium
No
No
7.64.0-r2 23.05.2019 SB2019052304
SB2019052305
SB2019052306
and 9 more
#VU17458 - Out-of-bounds read
CVE-2019-3823
CWE-125 Low
No
No
7.61.1-r2 11.02.2019 SB2019021102
SB2019020715
SB2019020716
and 14 more
#VU17457 - Out-of-bounds read
CVE-2018-16890
CWE-125 Low
No
No
7.61.1-r2 11.02.2019 SB2019021102
SB2019020715
SB2019020716
and 13 more
#VU17456 - Stack-based buffer overflow
CVE-2019-3822
CWE-121 High
No
No
7.61.1-r2 11.02.2019 SB2019021102
SB2019020715
SB2019020716
and 17 more
#VU15673 - Heap-based Buffer Overflow
CVE-2018-16842
CWE-122 Low
No
No
7.61.1-r1, 7.62.0-r0 01.11.2018 SB2018110105
SB2018110106
SB2018110302
and 20 more
#VU15671 - Integer overflow
CVE-2018-16839
CWE-190 High
No
No
7.61.1-r1, 7.62.0-r0 01.11.2018 SB2018110105
SB2018110106
SB2018110302
and 14 more
#VU15672 - Use After Free
CVE-2018-16840
CWE-416 Low
No
No
7.61.1-r1, 7.62.0-r0 01.11.2018 SB2018110105
SB2018110106
SB2018110610
and 19 more
#VU33489 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-3823
CWE-79 Low
No
No
7.64.0-r0 19.09.2018 SB2019020627
#VU33487 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-16980
CWE-79 Low
No
No
7.64.0-r0 13.09.2018 SB2018091311
SB2019020625
#VU14691 - Buffer overflow
CVE-2018-14618
CWE-120 High
No
No
7.61.1-r0 06.09.2018 SB2018090709
SB2018090710
SB2018090712
and 13 more
#VU13841 - Heap-based Buffer Overflow
CVE-2018-0500
CWE-122 High
No
No
7.61.0-r0 12.07.2018 SB2018071205
SB2018071207
SB2018071701
and 11 more
#VU33488 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2018-3822
CWE-22 High
No
No
7.64.0-r0 30.03.2018 SB2019020626


Showing elements 1 - 20 out of 68