Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 47

Количество 47

fstec логотип

BDU:2024-07759

около 3 лет назад

Уязвимость функции HandleData() пакета crypto/tls языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
altlinux логотип

ALT-PU-2024-1825

больше 2 лет назад

ALT-PU-2024-1825: package `golang` update to version 1.21.6-alt1

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-39322

около 3 лет назад

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-39322

около 3 лет назад

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-39322

около 3 лет назад

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-39322

около 3 лет назад

QUIC connections do not set an upper bound on the amount of data buffe ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2023-29409

около 3 лет назад

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2023-29409

около 3 лет назад

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-29409

около 3 лет назад

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2023-29409

22 дня назад

Large RSA keys can cause high CPU usage in crypto/tls

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-29409

около 3 лет назад

Extremely large RSA keys in certificate chains can cause a client/serv ...

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20241001-02

почти 2 года назад

Множественные уязвимости golang

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-892h-r6cr-53g4

около 3 лет назад

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3888-1

около 3 лет назад

Security update for Golang Prometheus

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3886-1

около 3 лет назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3263-1

около 3 лет назад

Security update for go1.19

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3181-1

около 3 лет назад

Security update for go1.20

EPSS: Низкий
github логотип

GHSA-xc82-5m89-g4jv

около 3 лет назад

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2023-06242

около 3 лет назад

Уязвимость пакета crypto/tls языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3841-1

около 3 лет назад

Security update for go1.19-openssl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-07759

Уязвимость функции HandleData() пакета crypto/tls языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
около 3 лет назад
altlinux логотип
ALT-PU-2024-1825

ALT-PU-2024-1825: package `golang` update to version 1.21.6-alt1

CVSS3: 9.8
больше 2 лет назад
ubuntu логотип
CVE-2023-39322

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-39322

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-39322

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-39322

QUIC connections do not set an upper bound on the amount of data buffe ...

CVSS3: 7.5
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-29409

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.

CVSS3: 5.3
2%
Низкий
около 3 лет назад
redhat логотип
CVE-2023-29409

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.

CVSS3: 5.3
2%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-29409

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.

CVSS3: 5.3
2%
Низкий
около 3 лет назад
msrc логотип
CVE-2023-29409

Large RSA keys can cause high CPU usage in crypto/tls

CVSS3: 5.3
2%
Низкий
22 дня назад
debian логотип
CVE-2023-29409

Extremely large RSA keys in certificate chains can cause a client/serv ...

CVSS3: 5.3
2%
Низкий
около 3 лет назад
redos логотип
ROS-20241001-02

Множественные уязвимости golang

CVSS3: 8.8
почти 2 года назад
github логотип
GHSA-892h-r6cr-53g4

QUIC connections do not set an upper bound on the amount of data buffered when reading post-handshake messages, allowing a malicious QUIC connection to cause unbounded memory growth. With fix, connections now consistently reject messages larger than 65KiB in size.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3888-1

Security update for Golang Prometheus

2%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3886-1

Security update for grafana

2%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3263-1

Security update for go1.19

2%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3181-1

Security update for go1.20

2%
Низкий
около 3 лет назад
github логотип
GHSA-xc82-5m89-g4jv

Extremely large RSA keys in certificate chains can cause a client/server to expend significant CPU time verifying signatures. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits. Based on a survey of publicly trusted RSA keys, there are currently only three certificates in circulation with keys larger than this, and all three appear to be test certificates that are not actively deployed. It is possible there are larger keys in use in private PKIs, but we target the web PKI, so causing breakage here in the interests of increasing the default safety of users of crypto/tls seems reasonable.

CVSS3: 5.3
2%
Низкий
около 3 лет назад
fstec логотип
BDU:2023-06242

Уязвимость пакета crypto/tls языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
2%
Низкий
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:3841-1

Security update for go1.19-openssl

около 3 лет назад

Уязвимостей на страницу