Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-3707

The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 50.8%
CVSS Severity
CVSS v2 Score 4.3
References
Products affected by CVE-2014-3707
  • Haxx » Libcurl » Version: 7.17.1
    cpe:2.3:a:haxx:libcurl:7.17.1
  • Haxx » Libcurl » Version: 7.18.0
    cpe:2.3:a:haxx:libcurl:7.18.0
  • Haxx » Libcurl » Version: 7.18.1
    cpe:2.3:a:haxx:libcurl:7.18.1
  • Haxx » Libcurl » Version: 7.18.2
    cpe:2.3:a:haxx:libcurl:7.18.2
  • Haxx » Libcurl » Version: 7.19.0
    cpe:2.3:a:haxx:libcurl:7.19.0
  • Haxx » Libcurl » Version: 7.19.1
    cpe:2.3:a:haxx:libcurl:7.19.1
  • Haxx » Libcurl » Version: 7.19.2
    cpe:2.3:a:haxx:libcurl:7.19.2
  • Haxx » Libcurl » Version: 7.19.3
    cpe:2.3:a:haxx:libcurl:7.19.3
  • Haxx » Libcurl » Version: 7.19.4
    cpe:2.3:a:haxx:libcurl:7.19.4
  • Haxx » Libcurl » Version: 7.19.5
    cpe:2.3:a:haxx:libcurl:7.19.5
  • Haxx » Libcurl » Version: 7.19.6
    cpe:2.3:a:haxx:libcurl:7.19.6
  • Haxx » Libcurl » Version: 7.19.7
    cpe:2.3:a:haxx:libcurl:7.19.7
  • Haxx » Libcurl » Version: 7.20.0
    cpe:2.3:a:haxx:libcurl:7.20.0
  • Haxx » Libcurl » Version: 7.20.1
    cpe:2.3:a:haxx:libcurl:7.20.1
  • Haxx » Libcurl » Version: 7.21.0
    cpe:2.3:a:haxx:libcurl:7.21.0
  • Haxx » Libcurl » Version: 7.21.1
    cpe:2.3:a:haxx:libcurl:7.21.1
  • Haxx » Libcurl » Version: 7.21.2
    cpe:2.3:a:haxx:libcurl:7.21.2
  • Haxx » Libcurl » Version: 7.21.3
    cpe:2.3:a:haxx:libcurl:7.21.3
  • Haxx » Libcurl » Version: 7.21.4
    cpe:2.3:a:haxx:libcurl:7.21.4
  • Haxx » Libcurl » Version: 7.21.5
    cpe:2.3:a:haxx:libcurl:7.21.5
  • Haxx » Libcurl » Version: 7.21.6
    cpe:2.3:a:haxx:libcurl:7.21.6
  • Haxx » Libcurl » Version: 7.21.7
    cpe:2.3:a:haxx:libcurl:7.21.7
  • Haxx » Libcurl » Version: 7.22.0
    cpe:2.3:a:haxx:libcurl:7.22.0
  • Haxx » Libcurl » Version: 7.23.0
    cpe:2.3:a:haxx:libcurl:7.23.0
  • Haxx » Libcurl » Version: 7.23.1
    cpe:2.3:a:haxx:libcurl:7.23.1
  • Haxx » Libcurl » Version: 7.24.0
    cpe:2.3:a:haxx:libcurl:7.24.0
  • Haxx » Libcurl » Version: 7.25.0
    cpe:2.3:a:haxx:libcurl:7.25.0
  • Haxx » Libcurl » Version: 7.26.0
    cpe:2.3:a:haxx:libcurl:7.26.0
  • Haxx » Libcurl » Version: 7.27.0
    cpe:2.3:a:haxx:libcurl:7.27.0
  • Haxx » Libcurl » Version: 7.28.0
    cpe:2.3:a:haxx:libcurl:7.28.0
  • Haxx » Libcurl » Version: 7.28.1
    cpe:2.3:a:haxx:libcurl:7.28.1
  • Haxx » Libcurl » Version: 7.29.0
    cpe:2.3:a:haxx:libcurl:7.29.0
  • Haxx » Libcurl » Version: 7.30.0
    cpe:2.3:a:haxx:libcurl:7.30.0
  • Haxx » Libcurl » Version: 7.31.0
    cpe:2.3:a:haxx:libcurl:7.31.0
  • Haxx » Libcurl » Version: 7.32.0
    cpe:2.3:a:haxx:libcurl:7.32.0
  • Haxx » Libcurl » Version: 7.33.0
    cpe:2.3:a:haxx:libcurl:7.33.0
  • Haxx » Libcurl » Version: 7.34.0
    cpe:2.3:a:haxx:libcurl:7.34.0
  • Haxx » Libcurl » Version: 7.35.0
    cpe:2.3:a:haxx:libcurl:7.35.0
  • Haxx » Libcurl » Version: 7.36.0
    cpe:2.3:a:haxx:libcurl:7.36.0
  • Haxx » Libcurl » Version: 7.37.0
    cpe:2.3:a:haxx:libcurl:7.37.0
  • Haxx » Libcurl » Version: 7.37.1
    cpe:2.3:a:haxx:libcurl:7.37.1
  • Haxx » Libcurl » Version: 7.38.0
    cpe:2.3:a:haxx:libcurl:7.38.0
  • Oracle » Hyperion » Version: 11.1.2.2
    cpe:2.3:a:oracle:hyperion:11.1.2.2
  • Oracle » Hyperion » Version: 11.1.2.3
    cpe:2.3:a:oracle:hyperion:11.1.2.3
  • Apple » Mac Os X » Version: 10.10.0
    cpe:2.3:o:apple:mac_os_x:10.10.0
  • Apple » Mac Os X » Version: 10.10.1
    cpe:2.3:o:apple:mac_os_x:10.10.1
  • Apple » Mac Os X » Version: 10.10.2
    cpe:2.3:o:apple:mac_os_x:10.10.2
  • Apple » Mac Os X » Version: 10.10.3
    cpe:2.3:o:apple:mac_os_x:10.10.3
  • Apple » Mac Os X » Version: 10.10.4
    cpe:2.3:o:apple:mac_os_x:10.10.4
  • Canonical » Ubuntu Linux » Version: 10.04
    cpe:2.3:o:canonical:ubuntu_linux:10.04
  • Canonical » Ubuntu Linux » Version: 12.04
    cpe:2.3:o:canonical:ubuntu_linux:12.04
  • Canonical » Ubuntu Linux » Version: 14.04
    cpe:2.3:o:canonical:ubuntu_linux:14.04
  • Canonical » Ubuntu Linux » Version: 14.10
    cpe:2.3:o:canonical:ubuntu_linux:14.10
  • Debian » Debian Linux » Version: 7.0
    cpe:2.3:o:debian:debian_linux:7.0
  • Debian » Debian Linux » Version: 8.0
    cpe:2.3:o:debian:debian_linux:8.0
  • Opensuse » Opensuse » Version: 13.1
    cpe:2.3:o:opensuse:opensuse:13.1
  • Opensuse » Opensuse » Version: 13.2
    cpe:2.3:o:opensuse:opensuse:13.2


Contact Us

Shodan ® - All rights reserved