peter bassill · operator
$ cve CVE-2019-5482 JSON

CVE-2019-5482

9.8
CRITICAL · CVSS 3.1 · EPSS 17.9% (pctl 97)

Patch early

EPSS 17.9% — above the 10% action threshold.

Description

Heap buffer overflow in the TFTP protocol handler in cURL 7.19.4 to 7.65.3.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS17.94% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-122
On CISA KEVno
Public exploitnone known
Published2019-09-16
Last modified2026-06-17

Affected (17)

VendorProduct
debiandebian linux
fedoraprojectfedora
haxxcurl
netappcloud backup
netapponcommand insight
netapponcommand unified manager
netapponcommand workflow automation
netappsnapcenter
netappsteelstore cloud integrated storage
opensuseleap
oraclecommunications operations monitor
oraclecommunications session border controller
oracleenterprise manager ops center
oraclehttp server
oraclehyperion essbase
oraclemysql server
oracleoss support tools

References

→ the Explorer  ·  watch your stack  ·  NVD