Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 61

Количество 61

rocky логотип

RLSA-2024:2549

около 2 лет назад

Moderate: skopeo security and bug fix update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-2549

около 2 лет назад

ELSA-2024-2549: skopeo security and bug fix update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3186-1

почти 2 года назад

Security update for buildah

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3151-1

почти 2 года назад

Security update for buildah

EPSS: Низкий
rocky логотип

RLSA-2024:3254

около 2 лет назад

Important: container-tools:rhel8 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3254

около 2 лет назад

ELSA-2024-3254: container-tools:ol8 security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3120-1

почти 2 года назад

Security update for buildah, docker

EPSS: Низкий
ubuntu логотип

CVE-2024-28180

больше 2 лет назад

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2024-28180

больше 2 лет назад

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-28180

больше 2 лет назад

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
EPSS: Низкий
msrc логотип

CVE-2024-28180

больше 1 года назад

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-28180

больше 2 лет назад

Package jose aims to provide an implementation of the Javascript Objec ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-24786

больше 2 лет назад

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-24786

больше 2 лет назад

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-24786

больше 2 лет назад

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2024-24786

больше 2 лет назад

EPSS: Низкий
debian логотип

CVE-2024-24786

больше 2 лет назад

The protojson.Unmarshal function can enter an infinite loop when unmar ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0066-1

больше 1 года назад

Security update for apptainer

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2754-1

почти 2 года назад

Security update for skopeo

EPSS: Низкий
github логотип

GHSA-c5q2-7r4c-mv6g

больше 2 лет назад

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2024:2549

Moderate: skopeo security and bug fix update

около 2 лет назад
oracle-oval логотип
ELSA-2024-2549

ELSA-2024-2549: skopeo security and bug fix update (MODERATE)

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:3186-1

Security update for buildah

почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3151-1

Security update for buildah

почти 2 года назад
rocky логотип
RLSA-2024:3254

Important: container-tools:rhel8 security update

около 2 лет назад
oracle-oval логотип
ELSA-2024-3254

ELSA-2024-3254: container-tools:ol8 security update (IMPORTANT)

около 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:3120-1

Security update for buildah, docker

почти 2 года назад
ubuntu логотип
CVE-2024-28180

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
2%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-28180

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
2%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-28180

Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now return an error if the decompressed data would exceed 250kB or 10x the compressed size (whichever is larger). This vulnerability has been patched in versions 4.0.1, 3.0.3 and 2.6.3.

CVSS3: 4.3
2%
Низкий
больше 2 лет назад
msrc логотип
CVSS3: 4.3
2%
Низкий
больше 1 года назад
debian логотип
CVE-2024-28180

Package jose aims to provide an implementation of the Javascript Objec ...

CVSS3: 4.3
2%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2024-24786

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-24786

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

CVSS3: 5.9
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-24786

The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
msrc логотип
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-24786

The protojson.Unmarshal function can enter an infinite loop when unmar ...

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2025:0066-1

Security update for apptainer

2%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2754-1

Security update for skopeo

2%
Низкий
почти 2 года назад
github логотип
GHSA-c5q2-7r4c-mv6g

Go JOSE vulnerable to Improper Handling of Highly Compressed Data (Data Amplification)

CVSS3: 4.3
2%
Низкий
больше 2 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.