Логотип exploitDog
bind:"CVE-2024-24791" OR bind:"CVE-2024-24789" OR bind:"CVE-2022-4122" OR bind:"CVE-2024-3727"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-24791" OR bind:"CVE-2024-24789" OR bind:"CVE-2022-4122" OR bind:"CVE-2024-3727"

Количество 81

Количество 81

github логотип

GHSA-hw49-2p59-3mhj

около 1 года назад

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending "Expect: 100-continue" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail.

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7349

10 месяцев назад

ELSA-2024-7349: grafana security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-06680

около 1 года назад

Уязвимость модуля net/http языка программирования Go, связанная с неправильной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
EPSS: Низкий
redos логотип

ROS-20241024-01

9 месяцев назад

Уязвимость golang

CVSS3: 5.9
EPSS: Низкий
oracle-oval логотип

ELSA-2024-9089

9 месяцев назад

ELSA-2024-9089: containernetworking-plugins security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2024-24789

около 1 года назад

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2024-24789

около 1 года назад

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-24789

около 1 года назад

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2024-24789

около 1 года назад

The archive/zip package's handling of certain types of invalid zip fil ...

CVSS3: 5.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-5258

12 месяцев назад

ELSA-2024-5258: container-tools:ol8 security update (IMPORTANT)

EPSS: Низкий
redos логотип

ROS-20240902-16

11 месяцев назад

Множественные уязвимости consul

CVSS3: 6.5
EPSS: Низкий
rocky логотип

RLSA-2024:6913

10 месяцев назад

Important: golang security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-6913

11 месяцев назад

ELSA-2024-6913: golang security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-6908

11 месяцев назад

ELSA-2024-6908: go-toolset:ol8 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-6969

10 месяцев назад

ELSA-2024-6969: container-tools:ol8 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7256

3 месяца назад

ELSA-2025-7256: git-lfs security update (MODERATE)

EPSS: Низкий
github логотип

GHSA-236w-p7wf-5ph8

около 1 года назад

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2024-04485

около 1 года назад

Уязвимость пакета archive-zip языка программирования Golang, позволяющая нарушителю создать произвольный zip-файл

CVSS3: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2022-4122

больше 2 лет назад

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-4122

больше 2 лет назад

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-hw49-2p59-3mhj

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending "Expect: 100-continue" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail.

0%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2024-7349

ELSA-2024-7349: grafana security update (MODERATE)

10 месяцев назад
fstec логотип
BDU:2024-06680

Уязвимость модуля net/http языка программирования Go, связанная с неправильной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
0%
Низкий
около 1 года назад
redos логотип
ROS-20241024-01

Уязвимость golang

CVSS3: 5.9
0%
Низкий
9 месяцев назад
oracle-oval логотип
ELSA-2024-9089

ELSA-2024-9089: containernetworking-plugins security update (MODERATE)

9 месяцев назад
ubuntu логотип
CVE-2024-24789

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
0%
Низкий
около 1 года назад
redhat логотип
CVE-2024-24789

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 7.5
0%
Низкий
около 1 года назад
nvd логотип
CVE-2024-24789

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-24789

The archive/zip package's handling of certain types of invalid zip fil ...

CVSS3: 5.5
0%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2024-5258

ELSA-2024-5258: container-tools:ol8 security update (IMPORTANT)

12 месяцев назад
redos логотип
ROS-20240902-16

Множественные уязвимости consul

CVSS3: 6.5
11 месяцев назад
rocky логотип
RLSA-2024:6913

Important: golang security update

10 месяцев назад
oracle-oval логотип
ELSA-2024-6913

ELSA-2024-6913: golang security update (IMPORTANT)

11 месяцев назад
oracle-oval логотип
ELSA-2024-6908

ELSA-2024-6908: go-toolset:ol8 security update (IMPORTANT)

11 месяцев назад
oracle-oval логотип
ELSA-2024-6969

ELSA-2024-6969: container-tools:ol8 security update (MODERATE)

10 месяцев назад
oracle-oval логотип
ELSA-2025-7256

ELSA-2025-7256: git-lfs security update (MODERATE)

3 месяца назад
github логотип
GHSA-236w-p7wf-5ph8

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
0%
Низкий
около 1 года назад
fstec логотип
BDU:2024-04485

Уязвимость пакета archive-zip языка программирования Golang, позволяющая нарушителю создать произвольный zip-файл

CVSS3: 6.2
0%
Низкий
около 1 года назад
ubuntu логотип
CVE-2022-4122

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2022-4122

A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу