Known vulnerabilities in curl (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:curl_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 40
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting curl (Red Hat package) curl (Red Hat package) is affected by 40 known vulnerabilities: 2 high, 24 medium, 14 low Critical High Medium Low

Vulnerabilities (40)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU115138 - Out-of-bounds read
CVE-2025-9086
CWE-125 Low
No
No
7.76.1-14.el9_0.12, 7.76.1-23.el9_2.8, 7.76.1-29.el9_4.3, 7.76.1-31.el9_6.2, 7.76.1-35.el9_7.3, 8.12.1-1.el10_0.4, 8.12.1-2.el10_1.2 10.09.2025 SB2025091034
SB2025091144
SB2025091301
and 44 more
#VU87850 - Missing Release of Resource after Effective Lifetime
CVE-2024-2398
CWE-772 Medium
No
No
7.76.1-23.el9_2.7, 7.76.1-29.el9_4.1 27.03.2024 SB2024032713
SB2024032740
SB2024032744
and 106 more
#VU83900 - Exposure of sensitive information to an unauthorized actor
CVE-2023-46218
CWE-200 Low
No
No
7.61.1-30.el8_8.9, 7.61.1-33.el8_9.5, 7.76.1-14.el9_0.11, 7.76.1-23.el9_2.6, 7.76.1-26.el9_3.3 06.12.2023 SB2023120612
SB2023120644
SB2023120661
and 87 more
#VU81865 - Heap-based Buffer Overflow
CVE-2023-38545
CWE-122 High
Available
No
7.76.1-14.el9_0.9, 7.76.1-23.el9_2.4, 7.76.1-26.el9_3.2 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 99 more
#VU81863 - External Control of File Name or Path
CVE-2023-38546
CWE-73 Low
No
No
7.61.1-22.el8_6.9, 7.61.1-30.el8_8.6, 7.61.1-33.el8_9.5, 7.76.1-14.el9_0.9, 7.76.1-23.el9_2.4, 7.76.1-26.el9_3.2 11.10.2023 SB2023101129
SB2023101135
SB2023101149
and 125 more
#VU76238 - Expected Behavior Violation
CVE-2023-28322
CWE-440 Medium
No
No
7.61.1-30.el8_8.9, 7.61.1-33.el8_9.5, 7.76.1-14.el9_0.7, 7.76.1-23.el9_2.2 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 88 more
#VU76237 - Improper Certificate Validation
CVE-2023-28321
CWE-295 Medium
No
No
7.61.1-22.el8_6.9, 7.61.1-30.el8_8.3, 7.76.1-14.el9_0.7, 7.76.1-23.el9_2.2 17.05.2023 SB2023051752
SB2023051760
SB2023051761
and 99 more
#VU73831 - Exposure of sensitive information to an unauthorized actor
CVE-2023-27538
CWE-200 Medium
No
No
7.76.1-26.el9 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 40 more
#VU73829 - State Issues
CVE-2023-27536
CWE-371 Medium
No
No
7.61.1-30.el8_8.3, 7.76.1-26.el9 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 80 more
#VU73828 - State Issues
CVE-2023-27535
CWE-371 Low
No
No
7.61.1-30.el8_8.2, 7.76.1-23.el9_2.1 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 84 more
#VU73827 - Improper input validation
CVE-2023-27534
CWE-20 Low
No
No
7.76.1-26.el9 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 45 more
#VU73826 - Improper input validation
CVE-2023-27533
CWE-20 Low
No
No
7.76.1-26.el9 20.03.2023 SB2023032027
SB2023032028
SB2023032044
and 42 more
#VU72337 - Allocation of Resources Without Limits or Throttling
CVE-2023-23916
CWE-770 Medium
No
No
7.61.1-18.el8_4.3, 7.61.1-22.el8_6.6, 7.61.1-25.el8_7.3, 7.76.1-14.el9_0.6, 7.76.1-19.el9_1.2 16.02.2023 SB2023021668
SB2023021670
SB2023021671
and 89 more
#VU70456 - Use After Free
CVE-2022-43552
CWE-416 Low
No
No
7.29.0-59.el7_9.2, 7.61.1-30.el8, 7.76.1-23.el9 21.12.2022 SB2022122102
SB2022122620
SB2022122621
and 66 more
#VU68746 - Expected Behavior Violation
CVE-2022-32221
CWE-440 Medium
No
No
7.76.1-14.el9_0.6, 7.76.1-19.el9_1.1 26.10.2022 SB2022102624
SB2022102643
SB2022102644
and 58 more
#VU66881 - Improper input validation
CVE-2022-35252
CWE-20 Medium
No
No
7.61.1-30.el8, 7.76.1-23.el9 31.08.2022 SB2022083106
SB2022090108
SB2022090217
and 55 more
#VU64685 - Improper Verification of Cryptographic Signature
CVE-2022-32208
CWE-347 Medium
No
No
7.61.1-22.el8_6.4, 7.76.1-14.el9_0.5 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 73 more
#VU64684 - Incorrect Default Permissions
CVE-2022-32207
CWE-276 Low
No
No
7.76.1-14.el9_0.5 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 35 more
#VU64682 - Resource exhaustion
CVE-2022-32206
CWE-400 Medium
No
No
7.61.1-18.el8_4.3, 7.61.1-22.el8_6.4, 7.76.1-14.el9_0.5 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 80 more
#VU62643 - Resource Management Errors
CVE-2022-27775
CWE-399 Low
No
No
7.76.1-19.el9 27.04.2022 SB2022042706
SB2022042803
SB2022042904
and 30 more


Showing elements 1 - 20 out of 40