Логотип exploitDog
bind:"CVE-2021-33198" OR bind:"CVE-2021-20291"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-33198" OR bind:"CVE-2021-20291"

Количество 27

Количество 27

oracle-oval логотип

ELSA-2022-7955

больше 2 лет назад

ELSA-2022-7955: skopeo security and bug fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8008

больше 2 лет назад

ELSA-2022-8008: buildah security and bug fix update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-20291

больше 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-20291

больше 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-20291

больше 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-20291

больше 4 лет назад

A deadlock vulnerability was found in 'github.com/containers/storage' ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-33198

около 4 лет назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-33198

больше 4 лет назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-33198

около 4 лет назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-33198

11 месяцев назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-33198

около 4 лет назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic fo ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7qw8-847f-pggm

около 4 лет назад

Improper Locking in github.com/containers/storage

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q2pw-fq43-w78v

около 3 лет назад

Go before 1.15.12 and 1.16.x before 1.16.5 attempts to allocate excessive memory (issue 2 of 2).

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-00723

около 4 лет назад

Уязвимость компонента math/big.Rat и метода unmarshaltext языка программирования Go, позволяющая нарушителю вызвать аварийный сбой и перезапуск устройства

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2021:4154

больше 3 лет назад

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2021-4154

больше 3 лет назад

ELSA-2021-4154: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10289

8 месяцев назад

ELSA-2024-10289: container-tools:ol8 security update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2214-1

около 4 лет назад

Security update for go1.15

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2186-1

около 4 лет назад

Security update for go1.16

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:0950-1

около 4 лет назад

Security update for go1.15

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2022-7955

ELSA-2022-7955: skopeo security and bug fix update (MODERATE)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-8008

ELSA-2022-8008: buildah security and bug fix update (MODERATE)

больше 2 лет назад
ubuntu логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which never finishes. An attacker could use this vulnerability to craft a malicious image, which when downloaded and stored by an application using containers/storage, would then cause a deadlock leading to a Denial of Service (DoS).

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-20291

A deadlock vulnerability was found in 'github.com/containers/storage' ...

CVSS3: 6.5
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
msrc логотип
CVSS3: 7.5
0%
Низкий
11 месяцев назад
debian логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic fo ...

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-7qw8-847f-pggm

Improper Locking in github.com/containers/storage

CVSS3: 6.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-q2pw-fq43-w78v

Go before 1.15.12 and 1.16.x before 1.16.5 attempts to allocate excessive memory (issue 2 of 2).

CVSS3: 7.5
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-00723

Уязвимость компонента math/big.Rat и метода unmarshaltext языка программирования Go, позволяющая нарушителю вызвать аварийный сбой и перезапуск устройства

CVSS3: 7.5
0%
Низкий
около 4 лет назад
rocky логотип
RLSA-2021:4154

Moderate: container-tools:rhel8 security, bug fix, and enhancement update

больше 3 лет назад
oracle-oval логотип
ELSA-2021-4154

ELSA-2021-4154: container-tools:ol8 security, bug fix, and enhancement update (MODERATE)

больше 3 лет назад
oracle-oval логотип
ELSA-2024-10289

ELSA-2024-10289: container-tools:ol8 security update (MODERATE)

8 месяцев назад
suse-cvrf логотип
openSUSE-SU-2021:2214-1

Security update for go1.15

около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:2186-1

Security update for go1.16

около 4 лет назад
suse-cvrf логотип
openSUSE-SU-2021:0950-1

Security update for go1.15

около 4 лет назад

Уязвимостей на страницу