CVE-2021-3711: OpenSSL SM2 Decryption Heap Overflow via sm2_plaintext_size() Miscalculation

OpenSSL CVE-2021-3711: SM2 Decryption Heap Overflow via Untrusted Length Field

posted 3 months ago

CVE-2022-3602: OpenSSL 3.0 punycode stack buffer overflow in X.509 name constraint verification

OpenSSL 3.0.6 CVE-2022-3602: Stack Buffer Overflow in Punycode Decoder

posted 3 months ago

CVE-2022-3602 OpenSSL punycode 4-byte stack overflow (SPOOKY-SSL)

CVE-2022-0778: OpenSSL BN_mod_sqrt infinite loop via non-prime modulus in Tonelli-Shanks

CVE-2022-0778 OpenSSL BN_mod_sqrt Infinite Loop in Tonelli-Shanks

CVE-2014-0160 Heartbleed: Missing bounds check in OpenSSL tls1_process_heartbeat

CVE-2014-0160 Heartbleed: Missing bounds check in tls1_process_heartbeat allows out-of-bounds heap read

CVE-2014-0160 Heartbleed: Unsanitized Payload Length in TLS Heartbeat Processing

posted 3 months ago

CVE-2020-8177: curl symlink attack via -J (Content-Disposition) and -i (include headers)

CVE-2020-8177: curl -J + -i local file overwrite via header-callback file creation bypass

CVE-2020-8177: curl local file overwrite via symlink with -J and -i options

CVE-2023-46218: Missing PSL Validation in Cookie Retrieval - curl Logic Bug

significantposted 3 months ago

CVE-2023-46218 — curl cookie mixed-case PSL bypass in Curl_cookie_add

CVE-2023-46218: curl cookie PSL check missing in Curl_cookie_getlist() — asymmetric validation logic-bug

CVE-2022-32221 curl POST-after-PUT use-after-free

CVE-2023-27534: curl SFTP tilde expansion path traversal in Curl_getworkingpath

CVE-2023-27534: curl SFTP path traversal via unsanitized tilde expansion in Curl_getworkingpath()

CVE-2023-27534: Path Traversal in curl SFTP Tilde Expansion

posted 3 months ago