CVE-2015-3237: Haxx Curl
Medium severity, CVSS 6.4. EPSS: 8.3% chance of exploitation in the next 30 days.
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values.
Affected products
- Haxx Curl: version 7.40.0 only; version 7.41.0 only; version 7.42.0 only; version 7.42.1 only
- Haxx Libcurl: version 7.40.0 only; version 7.41.0 only; version 7.42.0 only; version 7.42.1 only
- HP System Management Homepage: up to and including 7.5.3.1
- Oracle Enterprise Manager Ops Center: version 12.1.4 only; version 12.2.2 only; version 12.3.2 only
- Oracle Glassfish Server: version 3.0.1 only; version 3.1.2 only
Published 2015-06-22. Last modified 2026-06-17.