Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-0036

31
FAUCET Score

CVE-2012-0036 describes a data-injection vulnerability in curl and libcurl versions prior to 7.24.0, stemming from improper handling of special characters in URLs. This flaw allows remote attackers to inject data, such as CRLF sequences, into IMAP, POP3, or SMTP protocol communications. With a CVSS score of 7.5, this vulnerability is considered highly severe, requiring no authentication and having a low attack complexity, potentially leading to partial compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, nor are there publicly available exploit modules or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
7.20.0CPE matchmatch criteria
cpe:2.3:a:curl:curl:7.20.0:*:*:*:*:*:*:*
7.20.1CPE matchmatch criteria
cpe:2.3:a:curl:curl:7.20.1:*:*:*:*:*:*:*
7.21.0CPE matchmatch criteria
cpe:2.3:a:curl:curl:7.21.0:*:*:*:*:*:*:*
7.21.1CPE matchmatch criteria
cpe:2.3:a:curl:curl:7.21.1:*:*:*:*:*:*:*
7.21.2CPE matchmatch criteria
cpe:2.3:a:curl:curl:7.21.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
16.72%
Probability of exploitation in next 30 days
EPSS Percentile
96.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.1672 is in the 95th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

jitsipatch availablevia llm_extracted
Fixed in: 7.23.1
View patch
sierra_wirelesspatch availablevia llm_extracted
Fixed in: 7.23.1
View patch

Vendor Advisories (3)

redhatCVE-2012-0036Moderate

curl: URL sanitization vulnerability

Jan 24, 2012
sierra_wirelessllm-sierra_wireless-5f155aad93fbce29HIGH

URL sanitization vulnerability

Jan 24, 2012
jitsillm-jitsi-d9fd75ecac073d56HIGH

URL sanitization vulnerability

Jan 24, 2012

References

curl.haxx.se / curl-url-sanitize.patch
Patch
curl.haxx.se / docs/adv_20120124.html
Vendor Advisory
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
lists.apple.com / archives/security-announce/2012/May/msg00001.html
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/48256
security.gentoo.org / glsa/glsa-201203-02.xml
github.com / bagder/curl/commit/75ca568fa1c19de4c5358fed246686de8467c238
h20566.www2.hpe.com / hpsc/doc/public/display
support.apple.com / kb/HT5281
debian.org / security/2012/dsa-2398
mandriva.com / security/advisories
oracle.com / technetwork/topics/security/cpujul2015-2367936.html
securityfocus.com / bid/51665
securitytracker.com / id/1032924