CVE-2019-5482

CRITICAL

Haxx Curl < 7.65.3 - Out-of-Bounds Write

Title source: rule

Description

Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.

Scores

CVSS v3 9.8
EPSS 0.0833
EPSS Percentile 92.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-122 CWE-787
Status published

Affected Products (29)

haxx/curl < 7.65.3
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
opensuse/leap
opensuse/leap
netapp/cloud_backup
netapp/oncommand_insight
netapp/oncommand_unified_manager
netapp/oncommand_unified_manager
netapp/oncommand_workflow_automation
netapp/snapcenter
netapp/steelstore_cloud_integrated_storage
oracle/communications_operations_monitor
oracle/communications_operations_monitor
... and 14 more

Timeline

Published Sep 16, 2019
Tracked Since Feb 18, 2026