curl / Docs / Vulnerability table / 4.0 vulnerabilities

Vulnerabilities in curl 4.0

curl version 4.0 was released on March 20 1998

It has the following 4 published security problems.

SFlawFirstLast
LCVE-2020-8284: trusting FTP PASV responses4.07.73.0
HCVE-2016-0754: remote filename path traversal in curl tool for Windows4.07.46.0
HCVE-2015-3153: sensitive HTTP server headers also sent to proxies4.07.42.0
MCVE-2014-3613: cookie leak with IP address as domain4.07.37.1

Further details

CVE data for 4.0 provided as JSON.

Changelog for curl 4.0

See vulnerability summary for the previous release: 3.12 or the subsequent release: 4.1