curl: negotiate not treated as connection-oriented (incomplete fix for CVE-2015-3148)
curl 7.6
Critical 9.8 Unfixed
2018-03-12≤ 7.6.1
Critical 9.8
2020-02-21≤ 7.6.1
Critical 9.8
2018-01-24≤ 7.6.1
curl: HTTP authentication leak in redirects
High 8.8
2005-02-21≤ 7.6.1
security flaw
High 7.5
2018-08-23≤ 7.6.1
Medium 6.8
2009-03-05≤ 7.6.1
curl: local file access via unsafe redirects
Medium 6.5
2022-06-01≤ 7.6.1
curl: auth/cookie leak on redirect
Medium 5.9
2018-04-23≤ 7.6.1
curl: printf floating point buffer overflow
Medium 5.7
2022-06-01≤ 7.6.1
curl: credential leak on redirect
Medium 5.3
2016-01-29≤ 7.6.1
Medium 5.3
2018-07-31≤ 7.6.1
curl: Invalid URL parsing with '#'
Medium 5.3
2018-08-01≤ 7.6.1
curl: Double-free in krb5 code
Medium 5.3
2018-07-31≤ 7.6.1
curl: Double-free in curl_maprintf
Medium 5.3
2018-08-01≤ 7.6.1
curl: Cookie injection for other servers
Medium 5.0
2013-04-29≤ 7.6.1
curl: Cookie domain suffix match vulnerability
Medium 5.0
2014-11-18≤ 7.6.1
curl: incorrect handling of IP addresses in cookie domain
Medium 5.0
2015-05-01≤ 7.6.1
curl: sensitive HTTP server headers also sent to proxies
Low 3.7
2020-12-14≤ 7.6.1
curl: FTP PASV command response can cause curl to connect to arbitrary host
Low 3.7
2022-09-23≤ 7.6.1
curl: Incorrect handling of control code characters in cookies
Low 2.4
2017-04-03≤ 7.6.1
curl: --write-out out of bounds read
N/A
2009-08-14≤ 7.6.1
N/A
2015-01-15≤ 7.6.1
N/A
2016-08-10≤ 7.6.1
N/A
2021-04-01≤ 7.6.1