CVE-2022-40304: Dictionary Corruption via Entity Reference Cycles in libxml2 v2.9.14
CVE-2022-40303: Integer overflow in libxml2 xmlParseCharData → xmlBufAdd with XML_PARSE_HUGE
CVE-2023-0286: OpenSSL X.509 x400Address type confusion — ASN1_STRING decoded, read as ASN1_TYPE
CVE-2023-0286: Type Confusion in OpenSSL X.509 GENERAL_NAME Processing
CVE-2021-3711: OpenSSL SM2 heap-overflow via sm2_plaintext_size miscalculation
CVE-2021-3711: SM2 Plaintext Size Miscalculation Leading to Heap Overflow
CVE-2022-3602: OpenSSL 3.0 stack buffer overflow in ossl_punycode_decode (off-by-one bounds check)
CVE-2022-3602: OpenSSL Punycode Decoder Stack Buffer Overflow
CVE-2022-0778: OpenSSL BN_mod_sqrt infinite loop with composite prime modulus
CVE-2022-0778 — OpenSSL BN_mod_sqrt infinite loop on non-prime modulus via crafted EC certificate
CVE-2022-0778: Infinite loop in BN_mod_sqrt Tonelli-Shanks algorithm
CVE-2014-0160 Heartbleed: missing bounds check in tls1_process_heartbeat enables OOB heap read
Heartbleed (CVE-2014-0160) - Out-of-bounds Read in OpenSSL TLS Heartbeat
CVE-2014-0160 Heartbleed: Missing bounds check in tls1_process_heartbeat allows out-of-bounds heap read
CVE-2020-8177: curl -J + -i symlink/file-overwrite via rename() in tool_header_cb
CVE-2020-8177: curl -J -i interaction enables local-file overwrite via early fopen("wb")
CVE-2020-8177: Curl local file overwrite via symlink with -i and -J flags
CVE-2023-46218: curl cookie domain PSL check absent in Curl_cookie_getlist() — asymmetric validation logic bug
CVE-2023-46218: curl cookie domain matching logic bug allows cross-domain leakage
CVE-2023-46218 curl cookie mixed-case PSL bypass in Curl_cookie_add