Known vulnerabilities in curl (Debian package) 7.64.0-4+deb10u1

Vendor: Debian
Version: 7.64.0-4+deb10u1
Software CPE: cpe:2.3:o:debian:curl_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 8
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting curl (Debian package) version 7.64.0-4+deb10u1 curl (Debian package) 7.64.0-4+deb10u1 is affected by 8 vulnerabilities: 5 medium, 3 low Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU51822 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2021-22890
CWE-300 Medium
No
No
7.64.0-4+deb10u2 31.03.2021 SB2021033111
SB2021040104
SB2021040117
and 15 more
#VU51821 - Exposure of sensitive information to an unauthorized actor
CVE-2021-22876
CWE-200 Medium
No
No
7.64.0-4+deb10u2 31.03.2021 SB2021033111
SB2021040104
SB2021040117
and 31 more
#VU48895 - Improper Check for Certificate Revocation
CVE-2020-8286
CWE-299 Medium
No
No
7.64.0-4+deb10u2 09.12.2020 SB2020120902
SB2020120915
SB2020120929
and 30 more
#VU48894 - Uncontrolled Recursion
CVE-2020-8285
CWE-674 Low
No
No
7.64.0-4+deb10u2 09.12.2020 SB2020120902
SB2020120915
SB2020120928
and 37 more
#VU48893 - Exposure of sensitive information to an unauthorized actor
CVE-2020-8284
CWE-200 Medium
No
No
7.64.0-4+deb10u2 09.12.2020 SB2020120902
SB2020120915
SB2020120927
and 31 more
#VU45794 - Expired pointer dereference
CVE-2020-8231
CWE-825 Low
No
No
7.64.0-4+deb10u2 20.08.2020 SB2020081916
SB2020082001
SB2020081920
and 29 more
#VU29292 - Exposure of sensitive information to an unauthorized actor
CVE-2020-8169
CWE-200 Medium
No
No
7.64.0-4+deb10u2 25.06.2020 SB2020062513
SB2020062514
SB2020063017
and 14 more
#VU29290 - Improper Neutralization of HTTP Headers for Scripting Syntax
CVE-2020-8177
CWE-644 Low
No
No
7.64.0-4+deb10u2 25.06.2020 SB2020062511
SB2020062514
SB2020063002
and 27 more