CVE-2015-3237: Haxx Curl

Medium severity, CVSS 6.4. EPSS: 8.3% chance of exploitation in the next 30 days.

The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.

Affected products

  • Haxx Curl: version 7.40.0 only; version 7.41.0 only; version 7.42.0 only; version 7.42.1 only
  • Haxx Libcurl: version 7.40.0 only; version 7.41.0 only; version 7.42.0 only; version 7.42.1 only
  • HP System Management Homepage: up to and including 7.5.3.1
  • Oracle Enterprise Manager Ops Center: version 12.1.4 only; version 12.2.2 only; version 12.3.2 only
  • Oracle Glassfish Server: version 3.0.1 only; version 3.1.2 only

Published 2015-06-22. Last modified 2026-06-17.