← All CVEs

CVE-2013-2174

medium · 6.8

Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.

6.8
CVSS
10.7%
EPSS (exploit prob.)
96th
EPSS percentile
2013-07-31
Published

AV:N/AC:M/Au:N/C:P/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
haxxcurl7.7
haxxcurl7.7.1
haxxcurl7.7.2
haxxcurl7.7.3
haxxcurl7.8
haxxcurl7.8.1
haxxcurl7.9
haxxcurl7.9.1
haxxcurl7.9.2
haxxcurl7.9.3
haxxcurl7.9.4
haxxcurl7.9.5
haxxcurl7.9.6
haxxcurl7.9.7
haxxcurl7.9.8
haxxcurl7.10
haxxcurl7.10.1
haxxcurl7.10.2
haxxcurl7.10.3
haxxcurl7.10.4
haxxcurl7.10.5
haxxcurl7.10.6
haxxcurl7.10.7
haxxcurl7.10.8
haxxcurl7.11.0
haxxcurl7.11.1
haxxcurl7.11.2
haxxcurl7.12.0
haxxcurl7.12.1
haxxcurl7.12.2
haxxcurl7.12.3
haxxcurl7.13.0
haxxcurl7.13.1
haxxcurl7.13.2
haxxcurl7.14.0
haxxcurl7.14.1
haxxcurl7.15.0
haxxcurl7.15.1
haxxcurl7.15.2
haxxcurl7.15.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-2174