Vulnerability
curl/libcurl: Integer overflows in URL parser
libcurl contains two integer overflows in the `curl_url_set()` function that if triggered, can lead to a too small buffer allocation and a subsequent heap buffer overflow. The flaws only exist on 32-bit architectures and require excessive string input lengths.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:LLow exploitation likelihood — defer if no other signals fire.
No VEX statements published for CVE-2019-5435. Vendors publish VEX (Vulnerability Exploitability eXchange) to assert per-product whether a CVE is actually exploitable in their distribution.
No exploitation, limited impact or prevalence