CVE detail
CVE-2025-0725
When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option, **using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 14.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://security.netapp.com/advisory/ntap-20250306-0009/security.netapp.com
No excerpt available.
Vendor Advisorysecurity.netapp.comFeb 5, 2025, 10:15 AM No excerpt available.
Exploitgithub.comFeb 5, 2025, 10:15 AM- http://www.openwall.com/lists/oss-security/2025/02/06/4www.openwall.com
No excerpt available.
Exploitwww.openwall.comFeb 5, 2025, 10:15 AM - http://www.openwall.com/lists/oss-security/2025/02/06/2www.openwall.com
No excerpt available.
Exploitwww.openwall.comFeb 5, 2025, 10:15 AM - http://www.openwall.com/lists/oss-security/2025/02/05/3www.openwall.com
No excerpt available.
Exploitwww.openwall.comFeb 5, 2025, 10:15 AM - https://hackerone.com/reports/2956023hackerone.com
No excerpt available.
Exploithackerone.comFeb 5, 2025, 10:15 AM No excerpt available.
Vendor Advisorycurl.seFeb 5, 2025, 10:15 AMNo excerpt available.
Vendor Advisorycurl.seFeb 5, 2025, 10:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-2961CVSS 7.3 · High
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT chara…
- CVE-2020-12465CVSS 6.7 · Medium
An array overflow was discovered in mt76_add_fragment in drivers/net/wireless/mediatek/mt76/dma.c in the Linux kernel before 5.5.10, aka CID-b102f0c522cf. An oversized packet with…
- CVE-2025-0167CVSS 3.4 · Low
When asked to use a `.netrc` file for credentials **and** to follow HTTP redirects, curl could leak the password used for the first host to the followed-to host under certain circ…
4 mentions - CVE-2022-27776CVSS 6.5 · Medium
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port nu…
- CVE-2022-27775CVSS 7.5 · High
An information disclosure vulnerability exists in curl 7.65.0 to 7.82.0 are vulnerable that by using an IPv6 address that was in the connection pool but with a different zone id i…
- CVE-2022-27774CVSS 5.7 · Medium
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows H…