Known vulnerabilities in curl (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:curl_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 39
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting curl (Debian package) curl (Debian package) is affected by 39 known vulnerabilities: 4 high, 20 medium, 15 low Critical High Medium Low

Vulnerabilities (39)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU83900 - Exposure of sensitive information to an unauthorized actor
CVE-2023-46218
CWE-200 Low
No
No
7.74.0-1.3+deb11u11, 7.88.1-10+deb12u5 06.12.2023 SB2023120612
SB2023120644
SB2023120661
and 87 more
#VU83899 - Missing Encryption of Sensitive Data
CVE-2023-46219
CWE-311 Medium
No
No
7.74.0-1.3+deb11u11, 7.88.1-10+deb12u5 06.12.2023 SB2023120612
SB2023120644
SB2023120661
and 31 more
#VU81865 - Heap-based Buffer Overflow
CVE-2023-38545
CWE-122 High
Available
No
7.74.0-1.3+deb11u10, 7.88.1-10+deb12u4 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 99 more
#VU81863 - External Control of File Name or Path
CVE-2023-38546
CWE-73 Low
No
No
7.74.0-1.3+deb11u10, 7.88.1-10+deb12u4 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 125 more
#VU78540 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2023-32001
CWE-367 Low
No
No
7.88.1-10+deb12u1 21.07.2023 SB2023072135
SB2023072137
SB2023072138
and 17 more
#VU72337 - Allocation of Resources Without Limits or Throttling
CVE-2023-23916
CWE-770 Medium
No
No
7.74.0-1.3+deb11u7 16.02.2023 SB2023021668
SB2023021670
SB2023021671
and 89 more
#VU70456 - Use After Free
CVE-2022-43552
CWE-416 Low
No
No
7.74.0-1.3+deb11u5 21.12.2022 SB2022122102
SB2022122620
SB2022122621
and 66 more
#VU68746 - Expected Behavior Violation
CVE-2022-32221
CWE-440 Medium
No
No
7.74.0-1.3+deb11u5 26.10.2022 SB2022102624
SB2022102643
SB2022102644
and 58 more
#VU64685 - Improper Verification of Cryptographic Signature
CVE-2022-32208
CWE-347 Medium
No
No
7.74.0-1.3+deb11u2 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 73 more
#VU64684 - Incorrect Default Permissions
CVE-2022-32207
CWE-276 Low
No
No
7.74.0-1.3+deb11u2 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 35 more
#VU64682 - Resource exhaustion
CVE-2022-32206
CWE-400 Medium
No
No
7.74.0-1.3+deb11u2 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 80 more
#VU64681 - Resource exhaustion
CVE-2022-32205
CWE-400 Medium
No
No
7.74.0-1.3+deb11u2 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 32 more
#VU63009 - Incorrect Implementation of Authentication Algorithm
CVE-2022-27782
CWE-303 Medium
No
No
7.74.0-1.3+deb11u2 11.05.2022 SB2022051112
SB2022051136
SB2022051170
and 68 more
#VU63008 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-27781
CWE-835 Medium
No
No
7.74.0-1.3+deb11u2 11.05.2022 SB2022051112
SB2022051136
SB2022051170
and 36 more
#VU62644 - Exposure of sensitive information to an unauthorized actor
CVE-2022-27776
CWE-200 Low
No
No
7.74.0-1.3+deb11u2 27.04.2022 SB2022042706
SB2022042803
SB2022042904
and 62 more
#VU62641 - Exposure of sensitive information to an unauthorized actor
CVE-2022-27774
CWE-200 Medium
No
No
7.74.0-1.3+deb11u2, 7.74.0-1.3+deb11u5, 7.74.0-1.3+deb11u7 27.04.2022 SB2022042706
SB2022042803
SB2022042904
and 57 more
#VU62640 - Improper Authentication
CVE-2022-22576
CWE-287 Medium
No
No
7.74.0-1.3+deb11u2 27.04.2022 SB2022042706
SB2022042803
SB2022042904
and 60 more
#VU56613 - Cleartext Transmission of Sensitive Information
CVE-2021-22946
CWE-319 Medium
No
No
7.74.0-1.3+deb11u2 15.09.2021 SB2021091514
SB2021091601
SB2021091715
and 53 more
#VU56610 - Double Free
CVE-2021-22945
CWE-415 Low
No
No
7.74.0-1.3+deb11u2 15.09.2021 SB2021091514
SB2021091601
SB2021091715
and 20 more
#VU55146 - Improper Certificate Validation
CVE-2021-22924
CWE-295 Medium
No
No
7.74.0-1.3+deb11u2 21.07.2021 SB2021072108
SB2021072162
SB2021072202
and 33 more


Showing elements 1 - 20 out of 39