curl vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the curl package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • L
Insufficient Comparison

<7.81.0-1ubuntu1.19
  • M
CVE-2024-8096

<7.81.0-1ubuntu1.18
  • M
Out-of-bounds Read

<7.81.0-1ubuntu1.17
  • M
CVE-2024-2398

<7.81.0-1ubuntu1.16
  • M
CVE-2023-46218

<7.81.0-1ubuntu1.15
  • H
Out-of-bounds Write

<7.81.0-1ubuntu1.14
  • L
CVE-2023-38546

<7.81.0-1ubuntu1.14
  • L
Improper Certificate Validation

<7.81.0-1ubuntu1.11
  • L
CVE-2023-28322

<7.81.0-1ubuntu1.11
  • L
Improper Authentication

<7.81.0-1ubuntu1.10
  • L
Arbitrary Code Injection

<7.81.0-1ubuntu1.10
  • L
Improper Authentication

<7.81.0-1ubuntu1.10
  • L
Directory Traversal

<7.81.0-1ubuntu1.10
  • M
Improper Authentication

<7.81.0-1ubuntu1.10
  • M
Allocation of Resources Without Limits or Throttling

<7.81.0-1ubuntu1.8
  • L
Cleartext Transmission of Sensitive Information

<7.81.0-1ubuntu1.8
  • L
Cleartext Transmission of Sensitive Information

<7.81.0-1ubuntu1.8
  • M
Cleartext Transmission of Sensitive Information

<7.81.0-1ubuntu1.7
  • M
Use After Free

<7.81.0-1ubuntu1.7
  • M
Exposure of Resource to Wrong Sphere

<7.81.0-1ubuntu1.6
  • M
Double Free

<7.81.0-1ubuntu1.6
  • M
Cleartext Transmission of Sensitive Information

<7.81.0-1ubuntu1.6
  • L
CVE-2022-35252

<7.81.0-1ubuntu1.4
  • M
Allocation of Resources Without Limits or Throttling

<7.81.0-1ubuntu1.3
  • M
Allocation of Resources Without Limits or Throttling

<7.81.0-1ubuntu1.3
  • M
Incorrect Default Permissions

<7.81.0-1ubuntu1.3
  • M
Out-of-bounds Write

<7.81.0-1ubuntu1.3
  • M
Server-Side Request Forgery (SSRF)

<7.81.0-1ubuntu1.2
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<7.81.0-1ubuntu1.2
  • M
Improper Certificate Validation

<7.81.0-1ubuntu1.2
  • M
Insufficiently Protected Credentials

<7.81.0-1ubuntu1.1
  • L
Insufficiently Protected Credentials

<7.81.0-1ubuntu1.1
  • L
CVE-2022-27775

<7.81.0-1ubuntu1.1
  • M
Missing Authentication for Critical Function

<7.81.0-1ubuntu1.1
  • M
Double Free

<7.74.0-1.3ubuntu2
  • M
Cleartext Transmission of Sensitive Information

<7.74.0-1.3ubuntu2
  • M
Insufficient Verification of Data Authenticity

<7.74.0-1.3ubuntu2
  • M
Use of Uninitialized Resource

<7.74.0-1.2ubuntu4
  • M
Use of Incorrectly-Resolved Name or Reference

<7.74.0-1.2ubuntu4
  • L
Missing Initialization of Resource

<7.74.0-1.2ubuntu4