Known vulnerabilities in curl - page 2

Software: curl
Software CPE: cpe:2.3:o:fedoraproject:curl:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 126
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting curl curl is affected by 126 known vulnerabilities: 18 high, 61 medium, 47 low Critical High Medium Low

Vulnerabilities (126)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU115138 - Out-of-bounds read
CVE-2025-9086
CWE-125 Low
No
No
8.9.1-4.fc41, 8.11.1-6.fc42, 8.15.0-7.fc43 10.09.2025 SB2025091034
SB2025091144
SB2025091301
and 44 more
#VU99865 - Comparison using wrong factors
CVE-2024-9681
CWE-1025 Low
No
No
8.9.1-3.fc41 06.11.2024 SB2024110621
SB2024110655
SB2024110656
and 30 more
#VU94715 - Double Free
CVE-2024-6197
CWE-415 Medium
No
No
8.6.0-9.fc40 24.07.2024 SB2024072431
SB2024080568
SB20240806402
and 11 more
#VU87850 - Missing Release of Resource after Effective Lifetime
CVE-2024-2398
CWE-772 Medium
No
No
8.2.1-5.fc39, 8.6.0-8.fc40 27.03.2024 SB2024032713
SB2024032740
SB2024032744
and 106 more
#VU87846 - Improper input validation
CVE-2024-2004
CWE-20 Low
No
No
8.2.1-5.fc39, 8.6.0-8.fc40 27.03.2024 SB2024032713
SB2024032740
SB2024032748
and 28 more
#VU83900 - Exposure of sensitive information to an unauthorized actor
CVE-2023-46218
CWE-200 Low
No
No
8.0.1-6.fc38, 8.2.1-4.fc39 06.12.2023 SB2023120612
SB2023120644
SB2023120661
and 87 more
#VU83899 - Missing Encryption of Sensitive Data
CVE-2023-46219
CWE-311 Medium
No
No
8.0.1-6.fc38, 8.2.1-4.fc39 06.12.2023 SB2023120612
SB2023120644
SB2023120661
and 31 more
#VU81865 - Heap-based Buffer Overflow
CVE-2023-38545
CWE-122 High
Available
No
7.85.0-12.fc37, 8.0.1-5.fc38, 8.2.1-3.fc39 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 99 more
#VU81863 - External Control of File Name or Path
CVE-2023-38546
CWE-73 Low
No
No
7.85.0-12.fc37, 8.0.1-5.fc38, 8.2.1-3.fc39 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 125 more
#VU80732 - Resource exhaustion
CVE-2023-38039
CWE-400 Medium
No
No
7.85.0-11.fc37, 8.0.1-4.fc38, 8.2.1-2.fc39 13.09.2023 SB2023091327
SB2023091363
SB2023091402
and 33 more
#VU78540 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2023-32001
CWE-367 Low
No
No
7.85.0-10.fc37, 8.0.1-3.fc38 21.07.2023 SB2023072135
SB2023072137
SB2023072138
and 17 more
#VU76238 - Expected Behavior Violation
CVE-2023-28322
CWE-440 Medium
No
No
7.85.0-9.fc37, 8.0.1-2.fc38 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 88 more
#VU76237 - Improper Certificate Validation
CVE-2023-28321
CWE-295 Medium
No
No
7.85.0-9.fc37, 8.0.1-2.fc38 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 99 more
#VU73831 - Exposure of sensitive information to an unauthorized actor
CVE-2023-27538
CWE-200 Medium
No
No
7.82.0-14.fc36, 7.85.0-8.fc37, 7.87.0-7.fc38 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 40 more
#VU73830 - Double Free
CVE-2023-27537
CWE-415 High
No
No
7.85.0-8.fc37, 7.87.0-7.fc38 20.03.2023 SB2023032027
SB2023032044
SB2023060527
and 15 more
#VU73829 - State Issues
CVE-2023-27536
CWE-371 Medium
No
No
7.82.0-14.fc36, 7.85.0-8.fc37, 7.87.0-7.fc38 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 80 more
#VU73828 - State Issues
CVE-2023-27535
CWE-371 Low
No
No
7.82.0-14.fc36, 7.85.0-8.fc37, 7.87.0-7.fc38 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 84 more
#VU73827 - Improper input validation
CVE-2023-27534
CWE-20 Low
No
No
7.82.0-14.fc36, 7.85.0-8.fc37, 7.87.0-7.fc38 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 45 more
#VU73826 - Improper input validation
CVE-2023-27533
CWE-20 Low
No
No
7.82.0-14.fc36, 7.85.0-8.fc37, 7.87.0-7.fc38 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 42 more
#VU72335 - Cleartext Transmission of Sensitive Information
CVE-2023-23914
CWE-319 Medium
No
No
7.85.0-6.fc37 16.02.2023 SB2023021668
SB2023021671
SB2023021672
and 29 more


Showing elements 21 - 40 out of 126