Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 98

Количество 98

suse-cvrf логотип

SUSE-SU-2024:2294-1

около 2 лет назад

Security update for go1.21

EPSS: Низкий
rocky логотип

RLSA-2024:7349

почти 2 года назад

Moderate: grafana security update

EPSS: Низкий
github логотип

GHSA-hw49-2p59-3mhj

около 2 лет назад

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending "Expect: 100-continue" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail.

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7349

почти 2 года назад

ELSA-2024-7349: grafana security update (MODERATE)

EPSS: Низкий
fstec логотип

BDU:2024-06680

около 2 лет назад

Уязвимость модуля net/http языка программирования Go, связанная с неправильной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
EPSS: Низкий
redos логотип

ROS-20241024-01

почти 2 года назад

Уязвимость golang

CVSS3: 5.9
EPSS: Низкий
redos логотип

ROS-20240902-15

около 2 лет назад

Уязвимость nomad

CVSS3: 5.9
EPSS: Низкий
oracle-oval логотип

ELSA-2024-9089

почти 2 года назад

ELSA-2024-9089: containernetworking-plugins security update (MODERATE)

EPSS: Низкий
altlinux логотип

ALT-PU-2024-9590

около 2 лет назад

ALT-PU-2024-9590: package `golang` update to version 1.22.5-alt1

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-24789

больше 2 лет назад

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2024-24789

больше 2 лет назад

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2024-24789

больше 2 лет назад

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2024-24789

около 1 года назад

Mishandling of corrupt central directory record in archive/zip

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-24789

больше 2 лет назад

The archive/zip package's handling of certain types of invalid zip fil ...

CVSS3: 5.5
EPSS: Низкий
rocky логотип

RLSA-2024:5258

около 2 лет назад

Important: container-tools:rhel8 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-5258

около 2 лет назад

ELSA-2024-5258: container-tools:ol8 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2024:9135

больше 1 года назад

Moderate: toolbox security update

EPSS: Низкий
rocky логотип

RLSA-2024:6913

почти 2 года назад

Important: golang security update

EPSS: Низкий
rocky логотип

RLSA-2024:6908

почти 2 года назад

Important: go-toolset:rhel8 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-6913

около 2 лет назад

ELSA-2024-6913: golang security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2024:2294-1

Security update for go1.21

1%
Низкий
около 2 лет назад
rocky логотип
RLSA-2024:7349

Moderate: grafana security update

1%
Низкий
почти 2 года назад
github логотип
GHSA-hw49-2p59-3mhj

The net/http HTTP/1.1 client mishandled the case where a server responds to a request with an "Expect: 100-continue" header with a non-informational (200 or higher) status. This mishandling could leave a client connection in an invalid state, where the next request sent on the connection will fail. An attacker sending a request to a net/http/httputil.ReverseProxy proxy can exploit this mishandling to cause a denial of service by sending "Expect: 100-continue" requests which elicit a non-informational response from the backend. Each such request leaves the proxy with an invalid connection, and causes one subsequent request using that connection to fail.

1%
Низкий
около 2 лет назад
oracle-oval логотип
ELSA-2024-7349

ELSA-2024-7349: grafana security update (MODERATE)

1%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-06680

Уязвимость модуля net/http языка программирования Go, связанная с неправильной проверкой входных данных, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
1%
Низкий
около 2 лет назад
redos логотип
ROS-20241024-01

Уязвимость golang

CVSS3: 5.9
1%
Низкий
почти 2 года назад
redos логотип
ROS-20240902-15

Уязвимость nomad

CVSS3: 5.9
1%
Низкий
около 2 лет назад
oracle-oval логотип
ELSA-2024-9089

ELSA-2024-9089: containernetworking-plugins security update (MODERATE)

почти 2 года назад
altlinux логотип
ALT-PU-2024-9590

ALT-PU-2024-9590: package `golang` update to version 1.22.5-alt1

CVSS3: 7.5
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-24789

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
redhat логотип
CVE-2024-24789

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-24789

The archive/zip package's handling of certain types of invalid zip files differs from the behavior of most zip implementations. This misalignment could be exploited to create an zip file with contents that vary depending on the implementation reading the file. The archive/zip package now rejects files containing these errors.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
msrc логотип
CVE-2024-24789

Mishandling of corrupt central directory record in archive/zip

CVSS3: 5.3
0%
Низкий
около 1 года назад
debian логотип
CVE-2024-24789

The archive/zip package's handling of certain types of invalid zip fil ...

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
rocky логотип
RLSA-2024:5258

Important: container-tools:rhel8 security update

около 2 лет назад
oracle-oval логотип
ELSA-2024-5258

ELSA-2024-5258: container-tools:ol8 security update (IMPORTANT)

около 2 лет назад
rocky логотип
RLSA-2024:9135

Moderate: toolbox security update

больше 1 года назад
rocky логотип
RLSA-2024:6913

Important: golang security update

почти 2 года назад
rocky логотип
RLSA-2024:6908

Important: go-toolset:rhel8 security update

почти 2 года назад
oracle-oval логотип
ELSA-2024-6913

ELSA-2024-6913: golang security update (IMPORTANT)

около 2 лет назад

Уязвимостей на страницу