#cold-baseline clear

CVE-2022-32221 curl POST-after-PUT use-after-free

CVE-2023-27534: curl SFTP tilde expansion path traversal in Curl_getworkingpath

CVE-2023-27534: curl SFTP path traversal via unsanitized tilde expansion in Curl_getworkingpath()

CVE-2023-27535: curl FTP connection reuse misses ACCT/ALT-USER credentials

CVE-2023-38545: curl SOCKS5 state machine TOCTOU heap overflow via non-persistent socks5_resolve_local flag

CVE-2023-38545: curl SOCKS5 heap overflow via stale local resolve flag

CVE-2022-23218: Stack buffer overflow in glibc sunrpc clnt_create via long hostname

CVE-2021-35942: glibc wordexp() integer overflow in w_addword via we_offs

CVE-2021-35942: Integer overflow in glibc wordexp() w_addword function

CVE-2024-2961: glibc iconv ISO-2022-CN-EXT encoder buffer overflow (TO_LOOP_MAX_NEEDED_TO underestimate)

CVE-2021-3999: glibc getcwd off-by-one buffer underflow/overflow (size==1)

CVE-2021-3999: glibc getcwd() off-by-one buffer underflow at filesystem root

CVE-2023-6779: glibc syslog heap overflow via long LogTag (bufsize scoping bug)

CVE-2023-6779: glibc __vsyslog_internal heap overflow via long openlog ident

CVE-2023-6246: glibc __vsyslog_internal heap-overflow via undersized malloc in syslog fallback path

CVE-2023-6246: glibc syslog heap buffer overflow in __vsyslog_internal

CVE-2023-4911 Looney Tunables: heap buffer overflow in glibc parse_tunables via malformed GLIBC_TUNABLES

CVE-2019-9924: bash rbash restricted-bypass via BASH_CMDS / assign_hashcmd

CVE-2019-9924: bash rbash escape via fall-back script interpretation and BASH_CMDS

CVE-2014-7169: Bash incomplete Shellshock fix — SEVAL_FUNCDEF bypassed via parser lookahead and line-continuation