Critical 9.8 Unfixed
2018-03-12≤ 7.1.1
curl: negotiate not treated as connection-oriented (incomplete fix for CVE-2015-3148)
curl: negotiate not treated as connection-oriented (incomplete fix for CVE-2015-3148)
curl: HTTP authentication leak in redirects
curl: local file access via unsafe redirects
curl: auth/cookie leak on redirect
curl: printf floating point buffer overflow
curl: credential leak on redirect
curl: Invalid URL parsing with '#'
curl: Double-free in curl_maprintf
curl: Cookie injection for other servers
curl: Cookie domain suffix match vulnerability
curl: incorrect handling of IP addresses in cookie domain
curl: sensitive HTTP server headers also sent to proxies
curl: FTP PASV command response can cause curl to connect to arbitrary host
curl: Incorrect handling of control code characters in cookies
curl: --write-out out of bounds read