cvedb.io
CVE-2016-7167
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2016-10-07T14:59:08.100 · Last modified 2026-06-17T00:52:43.360

Summary

Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length 0xffffffff, which triggers a heap-based buffer overflow.

Affected products

fedoraproject — fedora

Does this affect you?

Add your gear to cvedb and we'll alert you only when fedoraproject ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.