← Vulnerability feed

Vulnerability record · CVE-2015-3237 · published 22 June 2015

CVE-2015-3237: Haxx curl improper input validation vulnerability

Haxx · Curl

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

6.4 CVSS 2.0 Medium EPSS 8.3% · top 5.3% CWE-20 · Improper input validation
6.4CVSS 2.0 base score
8.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
22References
17 Jun 2026Last modified by NVD

Description

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

AV:N/AC:L/Au:N/C:P/I:N/A:P

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://curl.haxx.se/docs/adv_20150617B.html Vendor Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160660.html
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securityfocus.com/bid/75387
http://www.securityfocus.com/bid/91787 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036371
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380
https://security.gentoo.org/glsa/201509-02
http://curl.haxx.se/docs/adv_20150617B.html Vendor Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/160660.html
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.securityfocus.com/bid/75387
http://www.securityfocus.com/bid/91787 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036371
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05111017 Third Party Advisory
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05158380
https://security.gentoo.org/glsa/201509-02

Track CVE-2015-3237 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2015-3113Adobe Flash Player heap buffer overflow allows remote code executionAdobe Flash Player contains a heap-based buffer overflow (CWE-122/CWE-787) reachable through unspecified vectors. It affects Flash Player before 13.0…KEVEPSS 100%analysed9.0CVE-2021-40438Apache HTTP Server mod_proxy SSRF via crafted URI pathA crafted request URI path can make mod_proxy forward the request to an origin server chosen by the remote user, an SSRF flaw in Apache HTTP Server 2…KEVEPSS 100%analysed8.8CVE-2015-8651Adobe Flash Player Integer Overflow Allows Remote Code ExecutionAdobe Flash Player, AIR, AIR SDK and AIR SDK & Compiler contain an integer overflow (CWE-190) that allows attackers to execute arbitrary code via uns…KEVEPSS 68%analysed7.8CVE-2019-0211Apache HTTP Server scoreboard use-after-free local privilege escalationApache HTTP Server 2.4.17 through 2.4.38 with MPM event, worker or prefork contains a use-after-free in scoreboard handling. Code running in a less-p…KEVEPSS 65%analysed10.0CVE-2012-2012Hp system management homepage vulnerabilityHP System Management Homepage (SMH) before 7.1.1 does not have an off autocomplete attribute for unspecified form fields, which makes it easier for r…EPSS 5.4%10.0CVE-2011-1541Hp system management homepage vulnerabilityUnspecified vulnerability in HP System Management Homepage (SMH) before 6.3 allows remote attackers to bypass intended access restrictions, and conse…EPSS 12%10.0CVE-2011-0807Oracle GlassFish and Sun Java System Application Server Administration flawAn unspecified vulnerability in the Administration component of Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, 3.0.1 and Sun Java System Applicat…EPSS 61%analysed9.8CVE-2026-19931Haxx curl vulnerabilityA flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is do…EPSS 0.75%

Source: NIST National Vulnerability Database (record CVE-2015-3237), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.