Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 12

Количество 12

github логотип

GHSA-gv3v-x3f3-7fxm

почти 2 года назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-8096

почти 2 года назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-8096

почти 2 года назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-8096

почти 2 года назад

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-8096

больше 1 года назад

OCSP stapling bypass with GnuTLS

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-8096

почти 2 года назад

When curl is told to use the Certificate Status Request TLS extension, ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3211-1

почти 2 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3204-1

почти 2 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3203-1

почти 2 года назад

Security update for curl

EPSS: Низкий
fstec логотип

BDU:2024-07774

почти 2 года назад

Уязвимость программного средства для взаимодействия с серверами curl, связанная c неправильной проверкой сертификата, позволяющая нарушителю оказывать влияние на целостность системы.

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20241001-29

почти 2 года назад

Уязвимость libcurl

CVSS3: 6.5
EPSS: Низкий
redos логотип

ROS-20241001-09

почти 2 года назад

Уязвимость curl

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-gv3v-x3f3-7fxm

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-8096

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-8096

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-8096

When curl is told to use the Certificate Status Request TLS extension, often referred to as OCSP stapling, to verify that the server certificate is valid, it might fail to detect some OCSP problems and instead wrongly consider the response as fine. If the returned status reports another error than 'revoked' (like for example 'unauthorized') it is not treated as a bad certficate.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
msrc логотип
CVE-2024-8096

OCSP stapling bypass with GnuTLS

CVSS3: 6.5
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-8096

When curl is told to use the Certificate Status Request TLS extension, ...

CVSS3: 6.5
1%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3211-1

Security update for curl

1%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3204-1

Security update for curl

1%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3203-1

Security update for curl

1%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-07774

Уязвимость программного средства для взаимодействия с серверами curl, связанная c неправильной проверкой сертификата, позволяющая нарушителю оказывать влияние на целостность системы.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
redos логотип
ROS-20241001-29

Уязвимость libcurl

CVSS3: 6.5
1%
Низкий
почти 2 года назад
redos логотип
ROS-20241001-09

Уязвимость curl

CVSS3: 6.5
1%
Низкий
почти 2 года назад

Уязвимостей на страницу