cbcvebase.

Debian Curl vulnerabilities

165 known vulnerabilities affecting debian/curl.

Total CVEs
165
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL23HIGH36MEDIUM65LOW41

Vulnerabilities

Page 9 of 9
CVE-2025-0167P4LOWCVSS 3.4fixed in curl 7.88.1-10+deb12u11 (bookworm)2025
CVE-2025-0167 [LOW] CVE-2025-0167: curl - When asked to use a `.netrc` file for credentials **and** to follow HTTP redirec... When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circumstances. This flaw only manifests itself if the netrc file has a `default` entry that omits both login and password. A rare circumstance. Scope: local bookworm: resolved (fixed in 7.88.1-10+deb
debian
CVE-2025-15224P4LOWCVSS 3.1fixed in curl 8.18.0-1 (forky)2025
CVE-2025-15224 [LOW] CVE-2025-15224: curl - When doing SSH-based transfers using either SCP or SFTP, and asked to do public ... When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 8.18.0-1) sid: resolved (fixed in 8.18.0-1) trixie: open
debian
CVE-2005-4077P4MEDIUMCVSS 4.6fixed in curl 7.15.1-1 (bookworm)2005
CVE-2005-4077 [MEDIUM] CVE-2005-4077: curl - Multiple off-by-one errors in the cURL library (libcurl) 7.11.2 through 7.15.0 a... Multiple off-by-one errors in the cURL library (libcurl) 7.11.2 through 7.15.0 allow local users to trigger a buffer overflow and cause a denial of service or bypass PHP security restrictions via certain URLs that (1) are malformed in a way that prevents a terminating null byte from being added to either a hostname or path buffer, or (2) contain a "?" separator in the
debian
CVE-2020-19909P4LOWCVSS 3.3fixed in curl 7.66.0-1 (bookworm)2020
CVE-2020-19909 [LOW] CVE-2020-19909: curl - Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large valu... Integer overflow vulnerability in tool_operate.c in curl 7.65.2 via a large value as the retry delay. NOTE: many parties report that this has no direct security impact on the curl user; however, it may (in theory) cause a denial of service to associated systems or networks if, for example, --retry-delay is misinterpreted as a value much smaller than what was intended. T
debian
CVE-2017-7407P4LOWCVSS 2.4fixed in curl 7.52.1-4 (bookworm)2017
CVE-2017-7407 [LOW] CVE-2017-7407: curl - The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physicall... The ourWriteOut function in tool_writeout.c in curl 7.53.1 might allow physically proximate attackers to obtain sensitive information from process memory in opportunistic circumstances by reading a workstation screen during use of a --write-out argument ending in a '%' character, which leads to a heap-based buffer over-read. Scope: local bookworm: resolved (fixed in 7.52.
debian
Debian Curl vulnerabilities | cvebase