Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 40

Количество 40

fstec логотип

BDU:2025-03456

больше 1 года назад

Уязвимость компонента crypto-elliptic языка программирования Golang, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 4
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:0431-1

больше 1 года назад

Security update for go1.24

EPSS: Низкий
redos логотип

ROS-20250226-17

больше 1 года назад

Уязвимость golang

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2024-45341

больше 1 года назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-45341

больше 1 года назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2024-45341

больше 1 года назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2024-45341

8 месяцев назад

Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-45341

больше 1 года назад

A certificate with a URI which has a IPv6 address with a zone ID may i ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2024-45336

больше 1 года назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2024-45336

больше 1 года назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-45336

больше 1 года назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2024-45336

больше 1 года назад

Sensitive headers incorrectly sent after cross-domain redirect in net/http

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-45336

больше 1 года назад

The HTTP client drops sensitive headers after following a cross-domain ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-3f6r-qh9c-x6mm

больше 1 года назад

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-03335

больше 1 года назад

Уязвимость языка программирования Golang, связанная с неправильной проверкой входных данных, позволяющая нарушителю обойти внедренные ограничения безопасности

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7wrw-r4p8-38rx

больше 1 года назад

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-02667

больше 1 года назад

Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

CVSS3: 6.1
EPSS: Низкий
rocky логотип

RLSA-2025:7592

10 месяцев назад

Important: yggdrasil security update

EPSS: Низкий
oracle-oval логотип

ELSA-2025-7592

около 1 года назад

ELSA-2025-7592: yggdrasil security update (IMPORTANT)

EPSS: Низкий
redos логотип

ROS-20250806-13

12 месяцев назад

Множественные уязвимости portainer-ce

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-03456

Уязвимость компонента crypto-elliptic языка программирования Golang, позволяющая нарушителю получить доступ к конфиденциальной информации

CVSS3: 4
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2025:0431-1

Security update for go1.24

больше 1 года назад
redos логотип
ROS-20250226-17

Уязвимость golang

CVSS2: 2.1
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-45341

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-45341

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 4.2
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-45341

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-45341

Usage of IPv6 zone IDs can bypass URI name constraints in crypto/x509

CVSS3: 6.1
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-45341

A certificate with a URI which has a IPv6 address with a zone ID may i ...

CVSS3: 6.1
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 5.9
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-45336

Sensitive headers incorrectly sent after cross-domain redirect in net/http

CVSS3: 6.1
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-45336

The HTTP client drops sensitive headers after following a cross-domain ...

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-3f6r-qh9c-x6mm

A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain. Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-03335

Уязвимость языка программирования Golang, связанная с неправильной проверкой входных данных, позволяющая нарушителю обойти внедренные ограничения безопасности

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-7wrw-r4p8-38rx

The HTTP client drops sensitive headers after following a cross-domain redirect. For example, a request to a.com/ containing an Authorization header which is redirected to b.com/ will not send that header to b.com. In the event that the client received a subsequent same-domain redirect, however, the sensitive headers would be restored. For example, a chain of redirects from a.com/, to b.com/1, and finally to b.com/2 would incorrectly send the Authorization header to b.com/2.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-02667

Уязвимость языка программирования Golang, связанная с недостаточной защитой служебных данных, позволяющая нарушителю получить несанкционированный доступ к учетным данным

CVSS3: 6.1
1%
Низкий
больше 1 года назад
rocky логотип
RLSA-2025:7592

Important: yggdrasil security update

10 месяцев назад
oracle-oval логотип
ELSA-2025-7592

ELSA-2025-7592: yggdrasil security update (IMPORTANT)

около 1 года назад
redos логотип
ROS-20250806-13

Множественные уязвимости portainer-ce

CVSS3: 9.1
12 месяцев назад

Уязвимостей на страницу