CVE-2016-4802: Haxx Curl
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Multiple untrusted search path vulnerabilities in cURL and libcurl before 7.49.1, when built with SSPI or telnet is enabled, allow local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) security.dll, (2) secur32.dll, or (3) ws2_32.dll in the application or current working directory.
Affected products
- Haxx Curl: up to and including 7.49.0
Published 2016-06-24. Last modified 2026-06-17.