Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 101

Количество 101

altlinux логотип

ALT-PU-2024-11781

около 2 лет назад

ALT-PU-2024-11781: package `golang` update to version 1.22.6-alt1

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20240422-05

больше 2 лет назад

Множественные уязвимости golang

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240805-08

около 2 лет назад

Множественные уязвимости consul

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2024:3830

больше 2 лет назад

Moderate: gvisor-tap-vsock security and bug fix update

EPSS: Низкий
github логотип

GHSA-rr6r-cfgf-gc6h

больше 2 лет назад

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-3831

больше 2 лет назад

ELSA-2024-3831: containernetworking-plugins security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3830

больше 2 лет назад

ELSA-2024-3830: gvisor-tap-vsock security and bug fix update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-02047

больше 2 лет назад

Уязвимость пакета golang операционной системы Debian GNU/Linux, позволяющая нарушителю вызвать отказ в обслуживании (DoS)

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-9089

почти 2 года назад

ELSA-2024-9089: containernetworking-plugins security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2024-24785

больше 2 лет назад

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 5.4
EPSS: Низкий
redhat логотип

CVE-2024-24785

больше 2 лет назад

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-24785

больше 2 лет назад

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 5.4
EPSS: Низкий
msrc логотип

CVE-2024-24785

8 месяцев назад

Errors returned from JSON marshaling may break template escaping in html/template

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-24785

больше 2 лет назад

If errors returned from MarshalJSON methods contain user controlled da ...

CVSS3: 5.4
EPSS: Низкий
rocky логотип

RLSA-2024:3827

больше 2 лет назад

Moderate: buildah security and bug fix update

EPSS: Низкий
rocky логотип

RLSA-2024:3826

больше 2 лет назад

Moderate: podman security and bug fix update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3827

больше 2 лет назад

ELSA-2024-3827: buildah security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-3826

больше 2 лет назад

ELSA-2024-3826: podman security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-9098

почти 2 года назад

ELSA-2024-9098: skopeo security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2024:8038

почти 2 года назад

Important: container-tools:rhel8 security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
altlinux логотип
ALT-PU-2024-11781

ALT-PU-2024-11781: package `golang` update to version 1.22.6-alt1

CVSS3: 9.8
около 2 лет назад
redos логотип
ROS-20240422-05

Множественные уязвимости golang

CVSS3: 7.5
больше 2 лет назад
redos логотип
ROS-20240805-08

Множественные уязвимости consul

CVSS3: 7.5
около 2 лет назад
rocky логотип
RLSA-2024:3830

Moderate: gvisor-tap-vsock security and bug fix update

1%
Низкий
больше 2 лет назад
github логотип
GHSA-rr6r-cfgf-gc6h

When parsing a multipart form (either explicitly with Request.ParseMultipartForm or implicitly with Request.FormValue, Request.PostFormValue, or Request.FormFile), limits on the total size of the parsed form were not applied to the memory consumed while reading a single form line. This permits a maliciously crafted input containing very long lines to cause allocation of arbitrarily large amounts of memory, potentially leading to memory exhaustion. With fix, the ParseMultipartForm function now correctly limits the maximum size of form lines.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2024-3831

ELSA-2024-3831: containernetworking-plugins security and bug fix update (MODERATE)

1%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2024-3830

ELSA-2024-3830: gvisor-tap-vsock security and bug fix update (MODERATE)

1%
Низкий
больше 2 лет назад
fstec логотип
BDU:2024-02047

Уязвимость пакета golang операционной системы Debian GNU/Linux, позволяющая нарушителю вызвать отказ в обслуживании (DoS)

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
oracle-oval логотип
ELSA-2024-9089

ELSA-2024-9089: containernetworking-plugins security update (MODERATE)

почти 2 года назад
ubuntu логотип
CVE-2024-24785

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-24785

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-24785

If errors returned from MarshalJSON methods contain user controlled data, they may be used to break the contextual auto-escaping behavior of the html/template package, allowing for subsequent actions to inject unexpected content into templates.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
msrc логотип
CVE-2024-24785

Errors returned from JSON marshaling may break template escaping in html/template

CVSS3: 5.4
1%
Низкий
8 месяцев назад
debian логотип
CVE-2024-24785

If errors returned from MarshalJSON methods contain user controlled da ...

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2024:3827

Moderate: buildah security and bug fix update

больше 2 лет назад
rocky логотип
RLSA-2024:3826

Moderate: podman security and bug fix update

больше 2 лет назад
oracle-oval логотип
ELSA-2024-3827

ELSA-2024-3827: buildah security and bug fix update (MODERATE)

больше 2 лет назад
oracle-oval логотип
ELSA-2024-3826

ELSA-2024-3826: podman security and bug fix update (MODERATE)

больше 2 лет назад
oracle-oval логотип
ELSA-2024-9098

ELSA-2024-9098: skopeo security update (MODERATE)

почти 2 года назад
rocky логотип
RLSA-2024:8038

Important: container-tools:rhel8 security update

почти 2 года назад

Уязвимостей на страницу