cbcvebase.
CVE-2010-0734
published 2010-03-19

CVE-2010-0734: content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that…

PriorityP428medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
5.48%
90.5th percentile
content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending crafted compressed data to an application that relies on the intended data-length limit.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl
curllibcurl

CVSS provenance

nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian6.8LOW
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.