<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 19:49:13 +0000</lastBuildDate>
    <item>
      <title>bdu:2019-04403</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2019-04403</link>
      <description>bdu:2019-04403</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2019-04403</guid>
    </item>
    <item>
      <title>certfr-2018-avi-339 — De multiples vulnérabilités ont été découvertes dans les produits
Juniper . Certaines d'entre elles permettent à un att…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2018-avi-339</link>
      <description>certfr-2018-avi-339</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2018-avi-339</guid>
    </item>
    <item>
      <title>cnvd-2018-04406</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2018-04406</link>
      <description>cnvd-2018-04406</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2018-04406</guid>
    </item>
    <item>
      <title>EUVD-2026-70995</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-70995</link>
      <description>EUVD-2026-70995</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-70995</guid>
    </item>
    <item>
      <title>fkie_cve-2018-1000007</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000007</link>
      <description>&lt;p&gt;libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the `Location:` response header value. Sending the same set of headers to subsequent hosts is in particular a problem for applications that pass on custom `Authorization:` headers, as this header often contains privacy sensitive information or data that could allow others to impersonate the libcurl-using client&amp;#39;s request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the `Location:` response header value. Sending the same set of headers to subsequent hosts is in particular a problem for applications that pass on custom `Authorization:` headers, as this header often contains privacy sensitive information or data that could allow others to impersonate the libcurl-using client&amp;#39;s request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2018-1000007</guid>
    </item>
    <item>
      <title>GHSA-g7x2-hrfp-pv5f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g7x2-hrfp-pv5f</link>
      <description>&lt;p&gt;libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the `Location:` response header value. Sending the same set of headers to subsequent hosts is in particular a problem for applications that pass on custom `Authorization:` headers, as this header often contains privacy sensitive information or data that could allow others to impersonate the libcurl-using client&amp;#39;s request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the `Location:` response header value. Sending the same set of headers to subsequent hosts is in particular a problem for applications that pass on custom `Authorization:` headers, as this header often contains privacy sensitive information or data that could allow others to impersonate the libcurl-using client&amp;#39;s request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g7x2-hrfp-pv5f</guid>
    </item>
    <item>
      <title>gsd-2018-1000007</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2018-1000007</link>
      <description>gsd-2018-1000007</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2018-1000007</guid>
    </item>
    <item>
      <title>RHSA-2018:3157 — security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:3157</link>
      <description>&lt;p&gt;security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:3157</guid>
    </item>
    <item>
      <title>RHSA-2018:3558 — Red Hat Security Advisory: httpd24 security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2018:3558</link>
      <description>&lt;p&gt;curl: TLS session resumption client cert bypass curl: Re-using connection with wrong client cert curl: Use of connection struct after free curl: Incorrect reuse of client certificates curl: escape and unescape integer overflows curl: Cookie injection for other servers curl: Case insensitive password comparison curl: Out-of-bounds write via unchecked multiplication curl: Double-free in curl_maprintf curl: Double-free in krb5 code curl: Glob parser write/read out of bounds curl: curl_getdate out-of-bounds read curl: URL unescape heap overflow via integer truncation curl: Use-after-free via shared cookies curl: Invalid URL parsing with &amp;#39;#&amp;#39; curl: IDNA 2003 makes curl use wrong host curl: printf floating point buffer overflow curl: --write-out out of bounds read curl: NTLM buffer overflow via integer overflow curl: FTP wildcard out of bounds read httpd: Out of bounds write in mod_authnz_ldap when using too small Accept-Language values httpd: &amp;lt;FilesMatch&amp;gt; bypass with a trailing newline in the file name curl: TFTP sends more than buffer size curl: URL globbing out of bounds read curl: FTP PWD response parser out of bounds read curl: IMAP FETCH response out of bounds read httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications httpd: Out of bounds access after failure in reading the HTTP request httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS httpd: Weak Digest auth nonce generatio…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;curl: TLS session resumption client cert bypass curl: Re-using connection with wrong client cert curl: Use of connection struct after free curl: Incorrect reuse of client certificates curl: escape and unescape integer overflows curl: Cookie injection for other servers curl: Case insensitive password comparison curl: Out-of-bounds write via unchecked multiplication curl: Double-free in curl_maprintf curl: Double-free in krb5 code curl: Glob parser write/read out of bounds curl: curl_getdate out-of-bounds read curl: URL unescape heap overflow via integer truncation curl: Use-after-free via shared cookies curl: Invalid URL parsing with &amp;#39;#&amp;#39; curl: IDNA 2003 makes curl use wrong host curl: printf floating point buffer overflow curl: --write-out out of bounds read curl: NTLM buffer overflow via integer overflow curl: FTP wildcard out of bounds read httpd: Out of bounds write in mod_authnz_ldap when using too small Accept-Language values httpd: &amp;lt;FilesMatch&amp;gt; bypass with a trailing newline in the file name curl: TFTP sends more than buffer size curl: URL globbing out of bounds read curl: FTP PWD response parser out of bounds read curl: IMAP FETCH response out of bounds read httpd: Improper handling of headers in mod_session can allow a remote user to modify session data for CGI applications httpd: Out of bounds access after failure in reading the HTTP request httpd: Out of bounds read in mod_cache_socache can allow a remote attacker to cause DoS httpd: Weak Digest auth nonce generatio…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2018:3558</guid>
    </item>
    <item>
      <title>SUSE-SU-2018:0214-1 — Security update for curl</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2018:0214-1</link>
      <description>&lt;p&gt;Security update for curl&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for curl&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2018:0214-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2018-1000007</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000007</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: curl, Ubuntu:16.04:LTS: curl&lt;/p&gt;
&lt;p&gt;libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the `Location:` response header value. Sending the same set of headers to subsequent hosts is in particular a problem for applications that pass on custom `Authorization:` headers, as this header often contains privacy sensitive information or data that could allow others to impersonate the libcurl-using client&amp;#39;s request.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: curl, Ubuntu:16.04:LTS: curl&lt;/p&gt;
&lt;p&gt;libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the `Location:` response header value. Sending the same set of headers to subsequent hosts is in particular a problem for applications that pass on custom `Authorization:` headers, as this header often contains privacy sensitive information or data that could allow others to impersonate the libcurl-using client&amp;#39;s request.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2018-1000007</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0890 — libcurl: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0890</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in libcurl ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Daten einzusehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in libcurl ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Daten einzusehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0890</guid>
    </item>
  </channel>
</rss>
