Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 22

Количество 22

ubuntu логотип

CVE-2025-58058

около 1 года назад

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-58058

около 1 года назад

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-58058

около 1 года назад

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2025-58058

около 1 года назад

github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-58058

около 1 года назад

xz is a pure golang package for reading and writing xz-compressed file ...

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20031-1

11 месяцев назад

Security update for warewulf4

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03448-1

12 месяцев назад

Security update for warewulf4

EPSS: Низкий
github логотип

GHSA-jc7w-c686-c4v9

около 1 года назад

github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2025-12797

около 1 года назад

Уязвимость языка программирования Go, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20192-1

8 месяцев назад

Security update for tailscale

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20073-1

10 месяцев назад

Security update for alloy

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0383-1

8 месяцев назад

Security update for rekor

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4121-1

10 месяцев назад

Security update for alloy

EPSS: Низкий
redos логотип

ROS-20251124-04

10 месяцев назад

Уязвимость golang-github-ulikunitz-xz

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20105-1

8 месяцев назад

Security update for sbctl

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21151-1

3 месяца назад

Security update for warewulf4

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20160-1

10 месяцев назад

Security update for hauler

EPSS: Низкий
altlinux логотип

ALT-PU-2026-10385

3 месяца назад

ALT-PU-2026-10385: package `prometheus-podman-exporter` update to version 1.21.2-alt1

CVSS3: 9.1
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20117-1

10 месяцев назад

Security update for trivy

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20798-1

7 месяцев назад

Security update for trivy

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-58058

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-58058

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-58058

xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.

CVSS3: 5.3
0%
Низкий
около 1 года назад
msrc логотип
CVE-2025-58058

github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives

CVSS3: 5.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-58058

xz is a pure golang package for reading and writing xz-compressed file ...

CVSS3: 5.3
0%
Низкий
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2025:20031-1

Security update for warewulf4

0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03448-1

Security update for warewulf4

0%
Низкий
12 месяцев назад
github логотип
GHSA-jc7w-c686-c4v9

github.com/ulikunitz/xz leaks memory when decoding a corrupted multiple LZMA archives

CVSS3: 5.3
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-12797

Уязвимость языка программирования Go, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
0%
Низкий
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2026:20192-1

Security update for tailscale

8 месяцев назад
suse-cvrf логотип
openSUSE-SU-2025:20073-1

Security update for alloy

10 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0383-1

Security update for rekor

8 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4121-1

Security update for alloy

10 месяцев назад
redos логотип
ROS-20251124-04

Уязвимость golang-github-ulikunitz-xz

CVSS3: 5.3
0%
Низкий
10 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20105-1

Security update for sbctl

8 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:21151-1

Security update for warewulf4

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2025:20160-1

Security update for hauler

10 месяцев назад
altlinux логотип
ALT-PU-2026-10385

ALT-PU-2026-10385: package `prometheus-podman-exporter` update to version 1.21.2-alt1

CVSS3: 9.1
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2025:20117-1

Security update for trivy

10 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20798-1

Security update for trivy

7 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.