Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2020-8285

curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing.

  • Published: Dec 14, 2020
  • Updated: Apr 14, 2023
  • CVE: CVE-2020-8285
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.5
  • AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:N/A:P
Software From Fixed in
haxx / libcurl 7.21.0 7.74.0
debian / debian_linux 9.0 9.0.x
debian / debian_linux 10.0 10.0.x
fedoraproject / fedora 32 32.x
fedoraproject / fedora 33 33.x
apple / mac_os_x - 10.14.6
apple / mac_os_x 10.15 10.15.7
apple / mac_os_x 10.14.6-security_update_2020-001 10.14.6-security_update_2020-001.x
apple / mac_os_x 10.14.6-security_update_2020-002 10.14.6-security_update_2020-002.x
apple / mac_os_x 10.14.6-security_update_2020-003 10.14.6-security_update_2020-003.x
apple / mac_os_x 10.14.6-security_update_2020-004 10.14.6-security_update_2020-004.x
apple / mac_os_x 10.14.6-security_update_2020-005 10.14.6-security_update_2020-005.x
apple / mac_os_x 10.14.6-security_update_2020-006 10.14.6-security_update_2020-006.x
apple / mac_os_x 10.14.6 10.14.6.x
apple / mac_os_x 10.15.7-supplemental_update 10.15.7-supplemental_update.x
apple / mac_os_x 10.15.7 10.15.7.x
apple / mac_os_x 10.14.6-security_update_2020-007 10.14.6-security_update_2020-007.x
apple / mac_os_x 10.14.6-security_update_2019-001 10.14.6-security_update_2019-001.x
apple / mac_os_x 10.14.6-security_update_2019-002 10.14.6-security_update_2019-002.x
apple / mac_os_x 10.15.7-security_update_2020-001 10.15.7-security_update_2020-001.x
apple / mac_os_x 10.14.6-security_update_2021-001 10.14.6-security_update_2021-001.x
apple / macos 11.0 11.3
apple / mac_os_x 10.15.7-security_update_2021-001 10.15.7-security_update_2021-001.x
oracle / peoplesoft_enterprise_peopletools 8.58 8.58.x
oracle / communications_billing_and_revenue_management 12.0.0.3.0 12.0.0.3.0.x
oracle / essbase 21.2 21.2.x
oracle / communications_cloud_native_core_policy 1.14.0 1.14.0.x
fujitsu / m10-1_firmware - xcp2410
fujitsu / m10-4_firmware - xcp2410
fujitsu / m10-4s_firmware - xcp2410
fujitsu / m12-1_firmware - xcp2410
fujitsu / m12-2_firmware - xcp2410
fujitsu / m12-2s_firmware - xcp2410
fujitsu / m10-1_firmware - xcp3110
fujitsu / m10-4_firmware - xcp3110
fujitsu / m10-4s_firmware - xcp3110
fujitsu / m12-1_firmware - xcp3110
fujitsu / m12-2_firmware - xcp3110
fujitsu / m12-2s_firmware - xcp3110
siemens / sinec_infrastructure_network_services - 1.0.1.1
splunk / universal_forwarder 9.1.0 9.1.0.x
splunk / universal_forwarder 9.0.0 9.0.6
splunk / universal_forwarder 8.2.0 8.2.12