Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 38

Количество 38

fstec логотип

BDU:2023-07013

почти 3 года назад

Уязвимость пакета http2 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20250822-12

около 1 года назад

Уязвимость stolon

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20250619-04

больше 1 года назад

Множественные уязвимости kubernetes

CVSS3: 7.5
EPSS: Низкий
altlinux логотип

ALT-PU-2023-6263

почти 3 года назад

ALT-PU-2023-6263: package `golang` update to version 1.21.3-alt1

CVSS3: 7.5
EPSS: Низкий
altlinux логотип

ALT-PU-2023-6262

почти 3 года назад

ALT-PU-2023-6262: package `golang` update to version 1.20.10-alt1

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240826-01

около 2 лет назад

Множественные уязвимости packer

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20240329-10

больше 2 лет назад

Множественные уязвимости cri-o

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2025-13603

11 месяцев назад

ALT-PU-2025-13603: package `flannel` update to version 0.27.3-alt1

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2023-39325

почти 3 года назад

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; s...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2023-39325

почти 3 года назад

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; s...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-39325

почти 3 года назад

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2023-39325

почти 3 года назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-39325

почти 3 года назад

A malicious HTTP/2 client which rapidly creates requests and immediate ...

CVSS3: 7.5
EPSS: Низкий
altlinux логотип

ALT-PU-2024-1825

больше 2 лет назад

ALT-PU-2024-1825: package `golang` update to version 1.21.6-alt1

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4374-p667-p6c8

почти 3 года назад

HTTP/2 rapid reset can cause excessive work in net/http

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4069-1

почти 3 года назад

Security update for go1.21

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4068-1

почти 3 года назад

Security update for go1.20

EPSS: Низкий
rocky логотип

RLSA-2023:6077

почти 3 года назад

Moderate: toolbox security update

EPSS: Низкий
rocky логотип

RLSA-2023:5863

почти 3 года назад

Moderate: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2023:5721

почти 3 года назад

Important: go-toolset:rhel8 security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2023-07013

Уязвимость пакета http2 языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
4%
Низкий
почти 3 года назад
redos логотип
ROS-20250822-12

Уязвимость stolon

CVSS3: 7.5
4%
Низкий
около 1 года назад
redos логотип
ROS-20250619-04

Множественные уязвимости kubernetes

CVSS3: 7.5
больше 1 года назад
altlinux логотип
ALT-PU-2023-6263

ALT-PU-2023-6263: package `golang` update to version 1.21.3-alt1

CVSS3: 7.5
почти 3 года назад
altlinux логотип
ALT-PU-2023-6262

ALT-PU-2023-6262: package `golang` update to version 1.20.10-alt1

CVSS3: 7.5
почти 3 года назад
redos логотип
ROS-20240826-01

Множественные уязвимости packer

CVSS3: 7.5
около 2 лет назад
redos логотип
ROS-20240329-10

Множественные уязвимости cri-o

CVSS3: 9.8
больше 2 лет назад
altlinux логотип
ALT-PU-2025-13603

ALT-PU-2025-13603: package `flannel` update to version 0.27.3-alt1

CVSS3: 9.1
11 месяцев назад
ubuntu логотип
CVE-2023-39325

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; s...

CVSS3: 7.5
4%
Низкий
почти 3 года назад
redhat логотип
CVE-2023-39325

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; s...

CVSS3: 7.5
4%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-39325

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see

CVSS3: 7.5
4%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 7.5
4%
Низкий
почти 3 года назад
debian логотип
CVE-2023-39325

A malicious HTTP/2 client which rapidly creates requests and immediate ...

CVSS3: 7.5
4%
Низкий
почти 3 года назад
altlinux логотип
ALT-PU-2024-1825

ALT-PU-2024-1825: package `golang` update to version 1.21.6-alt1

CVSS3: 9.8
больше 2 лет назад
github логотип
GHSA-4374-p667-p6c8

HTTP/2 rapid reset can cause excessive work in net/http

CVSS3: 7.5
4%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:4069-1

Security update for go1.21

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:4068-1

Security update for go1.20

почти 3 года назад
rocky логотип
RLSA-2023:6077

Moderate: toolbox security update

почти 3 года назад
rocky логотип
RLSA-2023:5863

Moderate: grafana security update

почти 3 года назад
rocky логотип
RLSA-2023:5721

Important: go-toolset:rhel8 security update

почти 3 года назад

Уязвимостей на страницу