Количество 31
Количество 31
GHSA-xrjj-mj9h-534m
golang.org/x/net/http2 vulnerable to possible excessive memory growth
CVE-2022-41717
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.
CVE-2022-41717
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.
CVE-2022-41717
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.
CVE-2022-41717
CVE-2022-41717
An attacker can cause excessive memory growth in a Go server accepting ...
ELSA-2023-2222
ELSA-2023-2222: conmon security and bug fix update (MODERATE)
BDU:2024-02376
Уязвимость пакета http2 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
SUSE-SU-2022:4398-1
Security update for go1.18
SUSE-SU-2022:4397-1
Security update for go1.19
ELSA-2023-2367
ELSA-2023-2367: containernetworking-plugins security and bug fix update (MODERATE)
ELSA-2023-2283
ELSA-2023-2283: skopeo security and bug fix update (MODERATE)
ELSA-2023-2282
ELSA-2023-2282: podman security and bug fix update (MODERATE)
ELSA-2023-2253
ELSA-2023-2253: buildah security and bug fix update (MODERATE)
ELSA-2023-2866
ELSA-2023-2866: git-lfs security and bug fix update (MODERATE)
ALT-PU-2022-3300
ALT-PU-2022-3300: package `golang` update to version 1.18.9-alt1
ALT-PU-2022-3297
ALT-PU-2022-3297: package `golang` update to version 1.19.4-alt1
ROS-20240327-01
Множественные уязвимости skopeo
ALT-PU-2023-1324
ALT-PU-2023-1324: package `traefik` update to version 2.9.8-alt1
ALT-PU-2023-1270
ALT-PU-2023-1270: package `traefik` update to version 2.9.8-alt1
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xrjj-mj9h-534m golang.org/x/net/http2 vulnerable to possible excessive memory growth | CVSS3: 5.3 | 6% Низкий | почти 4 года назад | |
CVE-2022-41717 An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection. | CVSS3: 5.3 | 6% Низкий | почти 4 года назад | |
CVE-2022-41717 An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection. | CVSS3: 5.3 | 6% Низкий | почти 4 года назад | |
CVE-2022-41717 An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection. | CVSS3: 5.3 | 6% Низкий | почти 4 года назад | |
CVSS3: 5.3 | 6% Низкий | почти 4 года назад | ||
CVE-2022-41717 An attacker can cause excessive memory growth in a Go server accepting ... | CVSS3: 5.3 | 6% Низкий | почти 4 года назад | |
ELSA-2023-2222 ELSA-2023-2222: conmon security and bug fix update (MODERATE) | 6% Низкий | больше 3 лет назад | ||
BDU:2024-02376 Уязвимость пакета http2 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.3 | 6% Низкий | почти 4 года назад | |
SUSE-SU-2022:4398-1 Security update for go1.18 | почти 4 года назад | |||
SUSE-SU-2022:4397-1 Security update for go1.19 | почти 4 года назад | |||
ELSA-2023-2367 ELSA-2023-2367: containernetworking-plugins security and bug fix update (MODERATE) | больше 3 лет назад | |||
ELSA-2023-2283 ELSA-2023-2283: skopeo security and bug fix update (MODERATE) | больше 3 лет назад | |||
ELSA-2023-2282 ELSA-2023-2282: podman security and bug fix update (MODERATE) | больше 3 лет назад | |||
ELSA-2023-2253 ELSA-2023-2253: buildah security and bug fix update (MODERATE) | больше 3 лет назад | |||
ELSA-2023-2866 ELSA-2023-2866: git-lfs security and bug fix update (MODERATE) | больше 3 лет назад | |||
ALT-PU-2022-3300 ALT-PU-2022-3300: package `golang` update to version 1.18.9-alt1 | CVSS3: 7.5 | почти 4 года назад | ||
ALT-PU-2022-3297 ALT-PU-2022-3297: package `golang` update to version 1.19.4-alt1 | CVSS3: 7.5 | почти 4 года назад | ||
ROS-20240327-01 Множественные уязвимости skopeo | CVSS3: 5.3 | больше 2 лет назад | ||
ALT-PU-2023-1324 ALT-PU-2023-1324: package `traefik` update to version 2.9.8-alt1 | CVSS3: 6.5 | больше 3 лет назад | ||
ALT-PU-2023-1270 ALT-PU-2023-1270: package `traefik` update to version 2.9.8-alt1 | CVSS3: 6.5 | больше 3 лет назад |
Уязвимостей на страницу