Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 163

Количество 163

redos логотип

ROS-20260507-73-0012

около 2 месяцев назад

Уязвимость golang

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20703-1

около 2 месяцев назад

Security update for coredns

EPSS: Низкий
ubuntu логотип

CVE-2026-32282

3 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
EPSS: Низкий
redhat логотип

CVE-2026-32282

3 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2026-32282

3 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
EPSS: Низкий
msrc логотип

CVE-2026-32282

26 дней назад

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

EPSS: Низкий
debian логотип

CVE-2026-32282

3 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while ...

CVSS3: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2026-32283

3 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-32283

3 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-32283

3 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-32283

2 месяца назад

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

EPSS: Низкий
debian логотип

CVE-2026-32283

3 месяца назад

If one side of the TLS connection sends multiple key update messages p ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:25999

9 дней назад

Moderate: yggdrasil-worker-package-manager security update

EPSS: Низкий
github логотип

GHSA-xj38-jxc5-rppx

3 месяца назад

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
EPSS: Низкий
fstec логотип

BDU:2026-07252

3 месяца назад

Уязвимость языка программирования Go, связанная с неверным определением ссылки перед доступом к файлу, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.4
EPSS: Низкий
rocky логотип

RLSA-2026:19139

30 дней назад

Important: go-fdo-client security update

EPSS: Низкий
rocky логотип

RLSA-2026:11881

около 2 месяцев назад

Important: grafana-pcp security update

EPSS: Низкий
github логотип

GHSA-jrg3-gfjw-hm96

3 месяца назад

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-11881

около 2 месяцев назад

ELSA-2026-11881: grafana-pcp security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-07246

3 месяца назад

Уязвимость языка программирования Go, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redos логотип
ROS-20260507-73-0012

Уязвимость golang

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20703-1

Security update for coredns

около 2 месяцев назад
ubuntu логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 7.8
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-32282

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

0%
Низкий
26 дней назад
debian логотип
CVE-2026-32282

On Linux, if the target of Root.Chmod is replaced with a symlink while ...

CVSS3: 6.4
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-32283

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

0%
Низкий
2 месяца назад
debian логотип
CVE-2026-32283

If one side of the TLS connection sends multiple key update messages p ...

CVSS3: 7.5
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:25999

Moderate: yggdrasil-worker-package-manager security update

0%
Низкий
9 дней назад
github логотип
GHSA-xj38-jxc5-rppx

On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.

CVSS3: 6.4
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-07252

Уязвимость языка программирования Go, связанная с неверным определением ссылки перед доступом к файлу, позволяющая нарушителю повысить свои привилегии

CVSS3: 6.4
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:19139

Important: go-fdo-client security update

0%
Низкий
30 дней назад
rocky логотип
RLSA-2026:11881

Important: grafana-pcp security update

0%
Низкий
около 2 месяцев назад
github логотип
GHSA-jrg3-gfjw-hm96

If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

CVSS3: 7.5
0%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-11881

ELSA-2026-11881: grafana-pcp security update (IMPORTANT)

около 2 месяцев назад
fstec логотип
BDU:2026-07246

Уязвимость языка программирования Go, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
3 месяца назад

Уязвимостей на страницу