libcurl是一款用于从服务器传输数据或向服务器传输数据的工具。 libcurl 存在安全漏洞,该漏洞源于libcurl 提供了使用 SHA 256 哈希验证 SSH 服务器公钥的功能,当此检查失败时,libcurl 会在返回包含(现已释放的)哈希的错误消息之前释放指纹的内存,导致信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | https://github.com/curl/curl | Fixed in 8.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-46945 | 9.1 CRITICAL | NagVis 路径遍历漏洞 |
| CVE-2023-2283 | libssh 授权问题漏洞 | |
| CVE-2023-27311 | NetApp BlueXP Cloud 路径遍历漏洞 | |
| CVE-2023-2898 | Linux kernel 代码问题漏洞 | |
| CVE-2023-33247 | Talend Data Catalog 安全漏洞 | |
| CVE-2023-33255 | Papaya 跨站脚本漏洞 | |
| CVE-2023-28320 | libcurl 资源管理错误漏洞 | |
| CVE-2023-28321 | curl 信任管理问题漏洞 | |
| CVE-2023-28322 | libcurl 安全漏洞 | |
| CVE-2023-1664 | Red Hat Keycloak 信任管理问题漏洞 | |
| CVE-2023-1667 | libssh 代码问题漏洞 | |
| CVE-2023-1981 | Avahi 资源管理错误漏洞 | |
| CVE-2023-20868 | Vmware NSX-T 跨站脚本漏洞 | |
| CVE-2023-22970 | Bottle 安全漏洞 | |
| CVE-2023-33394 | skycaiji 跨站脚本漏洞 | |
| CVE-2023-33439 | Faculty Evaluation System SQL注入漏洞 | |
| CVE-2023-33440 | Faculty Evaluation System 安全漏洞 | |
| CVE-2023-33720 | MP4v2 资源管理错误漏洞 | |
| CVE-2023-20882 | Cloud Foundry 安全漏洞 | |
| CVE-2023-20883 | Spring Framework 资源管理错误漏洞 |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet