VYPR
Unrated severityNVD Advisory· Published Nov 18, 2014· Updated Jun 17, 2026

CVE-2014-3620

CVE-2014-3620

Description

cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

20
  • Curl/Curl9 versions
    cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:*range: <=7.37.1
    • cpe:2.3:a:haxx:curl:7.31.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:curl:7.32.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:curl:7.33.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:curl:7.34.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:curl:7.35.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:curl:7.36.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:curl:7.37.0:*:*:*:*:*:*:*
    • (no CPE)range: <7.38.0
  • Curl/Libcurl9 versions
    cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:haxx:libcurl:*:*:*:*:*:*:*:*range: <=7.37.1
    • cpe:2.3:a:haxx:libcurl:7.31.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.32.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.33.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.34.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.35.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.36.0:*:*:*:*:*:*:*
    • cpe:2.3:a:haxx:libcurl:7.37.0:*:*:*:*:*:*:*
    • (no CPE)range: <7.38.0
  • cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*
    Range: <=10.10.4

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.