curl: negotiate not treated as connection-oriented (incomplete fix for CVE-2015-3148)
curl 7.8
curl: HTTP authentication leak in redirects
curl: POST following PUT confusion
curl: TELNET option IAC injection
security flaw
curl: local file access via unsafe redirects
curl: Loop counter error, leading to heap-based buffer overflow when decoding certain URLs
wrong proxy connection reuse with credentials
curl: auth/cookie leak on redirect
curl: printf floating point buffer overflow
curl: credential leak on redirect
curl: Invalid URL parsing with '#'
curl: Double-free in krb5 code
curl: Double-free in curl_maprintf
curl: Cookie injection for other servers
curl: Incorrect fix for CVE-2021-22898 TELNET stack contents disclosure
curl: more POST-after-PUT confusion
curl: Cookie domain suffix match vulnerability
curl: incorrect handling of IP addresses in cookie domain
curl: sensitive HTTP server headers also sent to proxies
curl: Case insensitive password comparison
curl: FTP PASV command response can cause curl to connect to arbitrary host
curl: Incorrect handling of control code characters in cookies
curl: Out-of-bounds write via unchecked multiplication
curl: TELNET stack contents disclosure
curl: --write-out out of bounds read