severity: critical clear

CVE-2020-8177: curl -J + -i symlink/file-overwrite via rename() in tool_header_cb

CVE-2020-8177: Curl local file overwrite via symlink with -i and -J flags

CVE-2023-46218: curl cookie domain PSL check absent in Curl_cookie_getlist() — asymmetric validation logic bug

CVE-2023-27534: curl SFTP path traversal via loose tilde-expansion check

CVE-2023-27534: curl SFTP path traversal via weak tilde-prefix check in Curl_getworkingpath

CVE-2023-38545: Heap Buffer Overflow in SOCKS5 Hostname Handling

CVE-2022-23218: Stack buffer overflow in glibc clnt_create() via unchecked strcpy into sun_path[108]

glibc CVE-2022-23218: Stack Buffer Overflow in clnt_create() with UNIX socket paths

CVE-2021-35942: Integer overflow in glibc wordexp() w_addword leads to heap overflow

CVE-2021-35942: Integer Overflow in glibc wordexp() w_addword Function

CVE-2024-2961: glibc iconv ISO-2022-CN-EXT buffer overflow — missing bounds checks in SS2/SS3 escape sequence writes

CVE-2024-2961: Buffer overflow in glibc ISO-2022-CN-EXT converter

CVE-2021-3999: glibc getcwd() off-by-one buffer underflow + missing bounds check

CVE-2021-3999: 1-byte buffer underflow in glibc __getcwd_generic at root

CVE-2021-3999: Off-by-One Buffer Underflow in glibc getcwd()

CVE-2023-6779: heap-overflow in glibc __vsyslog_internal via uninitialized bufsize in secondary buffer path

CVE-2023-6779: glibc __vsyslog_internal heap overflow via secondary buffer expansion

CVE-2023-6779: Heap Overflow in glibc syslog via Secondary Buffer Allocation

CVE-2023-6246: glibc __vsyslog_internal heap overread via undersized malloc in fallback path

CVE-2023-6246: Heap overflow in glibc __vsyslog_internal due to undersized malloc