Known vulnerabilities in curl - page 4
Vendor:
Fedoraproject
Software:
curl
Software CPE:
cpe:2.3:o:fedoraproject:curl:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
126
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
8.15.0-9.fc43
8.18.0-9.fc44
8.15.0-8.fc43
8.18.0-8.fc44
8.21.0~rc2-2.fc45
8.15.0-7.fc43
8.11.1-8.fc42
8.15.0-6.fc43
8.18.0-6.fc44
8.11.1-6.fc42
8.9.1-4.fc41
7.69.1-7.fc32
7.71.1-8.fc33
7.66.0-3.fc31
7.69.1-5.fc32
7.69.1-4.fc32
7.66.0-2.fc31
7.61.1-12.fc29
7.65.3-4.fc30
7.66.0-1.fc31
7.64.0-7.fc30
7.61.1-11.fc29
7.61.1-8.fc29
7.61.1-7.fc29
7.61.1-5.fc29
7.59.0-9.fc28
7.61.1-4.fc29
7.59.0-8.fc28
7.59.0-7.fc28
7.61.1-1.fc29
7.55.1-14.fc27
7.59.0-5.fc28
7.59.0-3.fc28
7.55.1-11.fc27
7.53.1-16.fc26
7.55.1-10.fc27
7.59.0-2.fc28
7.59.0-1.fc28
7.53.1-14.fc26
7.55.1-9.fc27
7.53.1-13.fc26
7.55.1-8.fc27
7.53.1-12.fc26
7.55.1-7.fc27
7.55.1-6.fc27
7.53.1-11.fc26
7.51.0-9.fc25
7.53.1-10.fc26
7.53.1-6.fc26
7.53.1-4.fc26
7.51.0-6.fc25
7.47.1-10.fc24
7.51.0-4.fc25
7.51.0-1.fc25
7.47.1-9.fc24
7.47.1-8.fc24
7.50.3-1.fc25
7.43.0-10.fc23
7.47.1-6.fc24
7.43.0-8.fc23
7.43.0-5.fc23
7.40.0-8.fc22
7.40.0-5.fc22
7.37.0-14.fc21
7.40.0-3.fc22
7.37.0-12.fc21
7.37.0-11.fc21
7.37.0-9.fc21
7.37.0-7.fc21
7.85.0-5.fc37
7.82.0-12.fc36
7.85.0-2.fc37
7.79.1-7.fc35
7.82.0-9.fc36
7.82.0-8.fc36
7.79.1-6.fc35
7.85.0-1.fc37
7.84.0-3.fc37
7.82.0-6.fc36
7.79.1-5.fc35
7.79.1-4.fc35
7.76.1-16.fc34
7.82.0-5.fc36
7.82.0-4.fc36
7.79.1-3.fc35
7.76.1-15.fc34
7.79.1-1.fc35
7.76.1-12.fc34
7.71.1-11.fc33
7.79.0-4.fc35
7.71.1-10.fc33
7.76.1-7.fc34
7.76.1-3.fc34
7.71.1-9.fc33
7.76.0-1.fc34
7.69.1-8.fc32
8.9.1-3.fc41
8.6.0-9.fc40
8.2.1-5.fc39
8.6.0-8.fc40
8.0.1-6.fc38
8.2.1-4.fc39
7.85.0-12.fc37
8.0.1-5.fc38
8.2.1-3.fc39
7.85.0-11.fc37
8.0.1-4.fc38
8.2.1-2.fc39
7.85.0-10.fc37
8.0.1-3.fc38
8.0.1-2.fc38
7.85.0-9.fc37
7.82.0-14.fc36
7.87.0-7.fc38
7.85.0-8.fc37
7.82.0-13.fc36
7.85.0-6.fc37
Vulnerabilities (126)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU62640 - Improper Authentication CVE-2022-22576 |
CWE-287 | Medium | 7.76.1-15.fc34, 7.76.1-16.fc34, 7.79.1-3.fc35, 7.79.1-4.fc35, 7.82.0-4.fc36 | 27.04.2022 |
SB2022042706 SB2022042803 SB2022042904 and 60 more |
||
| #VU56615 - Insufficient Verification of Data Authenticity CVE-2021-22947 |
CWE-345 | Medium | 7.71.1-11.fc33, 7.76.1-12.fc34, 7.79.0-4.fc35, 7.79.1-1.fc35 | 15.09.2021 |
SB2021091514 SB2021091601 SB2021091715 and 43 more |
||
| #VU56613 - Cleartext Transmission of Sensitive Information CVE-2021-22946 |
CWE-319 | Medium | 7.71.1-11.fc33, 7.76.1-12.fc34, 7.79.0-4.fc35, 7.79.1-1.fc35 | 15.09.2021 |
SB2021091514 SB2021091601 SB2021091715 and 53 more |
||
| #VU56610 - Double Free CVE-2021-22945 |
CWE-415 | Low | 7.71.1-11.fc33, 7.76.1-12.fc34, 7.79.0-4.fc35, 7.79.1-1.fc35 | 15.09.2021 |
SB2021091514 SB2021091601 SB2021091715 and 20 more |
||
| #VU55149 - Use of Uninitialized Variable CVE-2021-22925 |
CWE-457 | Medium | 7.71.1-10.fc33, 7.76.1-7.fc34 | 21.07.2021 |
SB2021072108 SB2021072162 SB2021072202 and 38 more |
||
| #VU55148 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2021-22922 |
CWE-611 | Medium | 7.71.1-10.fc33, 7.76.1-7.fc34 | 21.07.2021 |
SB2021072108 SB2021072162 SB2021072204 and 27 more |
||
| #VU55146 - Improper Certificate Validation CVE-2021-22924 |
CWE-295 | Medium | 7.71.1-10.fc33, 7.76.1-7.fc34 | 21.07.2021 |
SB2021072108 SB2021072162 SB2021072202 and 33 more |
||
| #VU55145 - Insufficiently Protected Credentials CVE-2021-22923 |
CWE-522 | Medium | 7.71.1-10.fc33, 7.76.1-7.fc34 | 21.07.2021 |
SB2021072108 SB2021072162 SB2021072204 and 28 more |
||
| #VU53589 - Use After Free CVE-2021-22901 |
CWE-416 | High | 7.76.1-3.fc34 | 26.05.2021 |
SB2021052620 SB2021052711 SB2021052719 and 18 more |
||
| #VU53587 - Use of Uninitialized Variable CVE-2021-22898 |
CWE-457 | Medium | 7.71.1-10.fc33, 7.76.1-3.fc34, 7.76.1-7.fc34 | 26.05.2021 |
SB2021052620 SB2021052711 SB2021060128 and 47 more |
||
| #VU51822 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2021-22890 |
CWE-300 | Medium | 7.69.1-8.fc32, 7.71.1-9.fc33, 7.76.0-1.fc34 | 31.03.2021 |
SB2021033111 SB2021040104 SB2021040117 and 15 more |
||
| #VU51821 - Exposure of sensitive information to an unauthorized actor CVE-2021-22876 |
CWE-200 | Medium | 7.69.1-8.fc32, 7.71.1-9.fc33, 7.76.0-1.fc34 | 31.03.2021 |
SB2021033111 SB2021040104 SB2021040117 and 31 more |
||
| #VU48895 - Improper Check for Certificate Revocation CVE-2020-8286 |
CWE-299 | Medium | 7.69.1-7.fc32, 7.71.1-8.fc33 | 09.12.2020 |
SB2020120902 SB2020120915 SB2020120929 and 30 more |
||
| #VU48894 - Uncontrolled Recursion CVE-2020-8285 |
CWE-674 | Low | 7.69.1-7.fc32, 7.71.1-8.fc33 | 09.12.2020 |
SB2020120902 SB2020120915 SB2020120928 and 37 more |
||
| #VU48893 - Exposure of sensitive information to an unauthorized actor CVE-2020-8284 |
CWE-200 | Medium | 7.69.1-7.fc32, 7.71.1-8.fc33 | 09.12.2020 |
SB2020120902 SB2020120915 SB2020120927 and 31 more |
||
| #VU45794 - Expired pointer dereference CVE-2020-8231 |
CWE-825 | Low | 7.66.0-3.fc31, 7.69.1-5.fc32 | 20.08.2020 |
SB2020081916 SB2020082001 SB2020081920 and 29 more |
||
| #VU29292 - Exposure of sensitive information to an unauthorized actor CVE-2020-8169 |
CWE-200 | Medium | 7.66.0-2.fc31, 7.69.1-4.fc32 | 25.06.2020 |
SB2020062513 SB2020062514 SB2020063017 and 14 more |
||
| #VU29290 - Improper Neutralization of HTTP Headers for Scripting Syntax CVE-2020-8177 |
CWE-644 | Low | 7.66.0-2.fc31, 7.69.1-4.fc32 | 25.06.2020 |
SB2020062511 SB2020062514 SB2020063002 and 27 more |
||
| #VU21059 - Heap-based Buffer Overflow CVE-2019-5482 |
CWE-122 | Medium | 7.61.1-12.fc29, 7.65.3-4.fc30, 7.66.0-1.fc31 | 11.09.2019 |
SB2019091142 SB2019091143 SB2019091201 and 28 more |
||
| #VU21058 - Double Free CVE-2019-5481 |
CWE-415 | Low | 7.61.1-12.fc29, 7.65.3-4.fc30, 7.66.0-1.fc31 | 11.09.2019 |
SB2019091142 SB2019091143 SB2019091201 and 12 more |
Showing elements 61 - 80 out of 126