Unrated severityNVD Advisory· Published Nov 18, 2014· Updated Jun 17, 2026
CVE-2014-3620
CVE-2014-3620
Description
cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
20cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*range: <=7.37.1
- cpe:2.3:a:haxx:curl:7.31.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:curl:7.32.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:curl:7.33.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:curl:7.34.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:curl:7.35.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:curl:7.36.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:curl:7.37.0:*:*:*:*:*:*:*
- (no CPE)range: <7.38.0
cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*range: <=7.37.1
- cpe:2.3:a:haxx:libcurl:7.31.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:libcurl:7.32.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:libcurl:7.33.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:libcurl:7.34.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:libcurl:7.35.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:libcurl:7.36.0:*:*:*:*:*:*:*
- cpe:2.3:a:haxx:libcurl:7.37.0:*:*:*:*:*:*:*
- (no CPE)range: <7.38.0
Patches
Vulnerability mechanics
References
8- curl.haxx.se/docs/adv_20140910B.htmlnvdPatchVendor Advisory
- www.debian.org/security/2014/dsa-3022nvdVendor Advisory
- support.apple.com/kb/HT205031nvdVendor Advisory
- kb.juniper.net/InfoCenter/indexnvd
- lists.apple.com/archives/security-announce/2015/Aug/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2014-09/msg00024.htmlnvd
- www.openwall.com/lists/oss-security/2022/05/11/2nvd
- www.securityfocus.com/bid/69742nvd
News mentions
0No linked articles in our index yet.