Логотип exploitDog
bind:"CVE-2025-22866" OR bind:"CVE-2024-45341" OR bind:"CVE-2024-45336"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-22866" OR bind:"CVE-2024-45341" OR bind:"CVE-2024-45336"

Количество 42

Количество 42

github логотип

GHSA-3whm-j4xm-rv8x

11 месяцев назад

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 8.4
EPSS: Низкий
fstec логотип

BDU:2025-03456

11 месяцев назад

Уязвимость компонента crypto-elliptic языка программирования Golang, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0431-1

10 месяцев назад

Security update for go1.24

EPSS: Низкий
redos логотип

ROS-20250226-17

10 месяцев назад

Уязвимость golang

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2024-45341

11 месяцев назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-45341

11 месяцев назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2024-45341

11 месяцев назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2024-45341

13 дней назад

Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-45341

11 месяцев назад

A certificate with a URI which has a IPv6 address with a zone ID may i ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2024-45336

11 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-45336

11 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-45336

11 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2024-45336

10 месяцев назад

Sensitive headers incorrectly sent after cross-domain redirect in net/http

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-45336

11 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3f6r-qh9c-x6mm

11 месяцев назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-03335

11 месяцев назад

Уязвимость языка программирования Golang, связанная с неправильной проверкой входных данных, позволяющая нарушителю обойти внедренные ограничения безопасности

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7wrw-r4p8-38rx

11 месяцев назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-02667

11 месяцев назад

Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0297-1

11 месяцев назад

Security update for govulncheck-vulndb

EPSS: Низкий
rocky логотип

RLSA-2025:7592

3 месяца назад

Important: yggdrasil security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3whm-j4xm-rv8x

Due to the usage of a variable time instruction in the assembly implementation of an internal function, a small number of bits of secret scalars are leaked on the ppc64le architecture. Due to the way this function is used, we do not believe this leakage is enough to allow recovery of the private key when P-256 is used in any well known protocols.

CVSS3: 8.4
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-03456

Уязвимость компонента crypto-elliptic языка программирования Golang, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 4
0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0431-1

Security update for go1.24

10 месяцев назад
redos логотип
ROS-20250226-17

Уязвимость golang

CVSS2: 2.1
0%
Низкий
10 месяцев назад
ubuntu логотип
CVE-2024-45341

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
redhat логотип
CVE-2024-45341

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 4.2
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2024-45341

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2024-45341

Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509

CVSS3: 6.1
0%
Низкий
13 дней назад
debian логотип
CVE-2024-45341

A certificate with a URI which has a IPv6 address with a zone ID may i ...

CVSS3: 6.1
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
redhat логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 5.9
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
msrc логотип
CVE-2024-45336

Sensitive headers incorrectly sent after cross-domain redirect in net/http

CVSS3: 6.1
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain ...

CVSS3: 6.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-3f6r-qh9c-x6mm

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-03335

Уязвимость языка программирования Golang, связанная с неправильной проверкой входных данных, позволяющая нарушителю обойти внедренные ограничения безопасности

CVSS3: 6.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-7wrw-r4p8-38rx

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
0%
Низкий
11 месяцев назад
fstec логотип
BDU:2025-02667

Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

CVSS3: 6.1
0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:0297-1

Security update for govulncheck-vulndb

11 месяцев назад
rocky логотип
RLSA-2025:7592

Important: yggdrasil security update

3 месяца назад

Уязвимостей на страницу