Логотип exploitDog
bind:"CVE-2021-33198" OR bind:"CVE-2024-9676" OR bind:"CVE-2021-4024"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2021-33198" OR bind:"CVE-2024-9676" OR bind:"CVE-2021-4024"

Количество 48

Количество 48

oracle-oval логотип

ELSA-2024-10289

7 месяцев назад

ELSA-2024-10289: container-tools:ol8 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-33198

почти 4 года назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-33198

больше 4 лет назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-33198

почти 4 года назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-33198

9 месяцев назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-33198

почти 4 года назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic fo ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q2pw-fq43-w78v

около 3 лет назад

Go before 1.15.12 and 1.16.x before 1.16.5 attempts to allocate excessive memory (issue 2 of 2).

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-00723

почти 4 года назад

Уязвимость компонента math/big.Rat и метода unmarshaltext языка программирования Go, позволяющая нарушителю вызвать аварийный сбой и перезапуск устройства

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-7955

больше 2 лет назад

ELSA-2022-7955: skopeo security and bug fix update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-4024

больше 3 лет назад

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-4024

больше 3 лет назад

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2021-4024

больше 3 лет назад

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-4024

больше 3 лет назад

A flaw was found in podman. The `podman machine` function (used to cre ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-9676

8 месяцев назад

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-9676

8 месяцев назад

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-9676

8 месяцев назад

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-9676

7 месяцев назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-9676

8 месяцев назад

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink tra ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2214-1

почти 4 года назад

Security update for go1.15

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2186-1

почти 4 года назад

Security update for go1.16

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2024-10289

ELSA-2024-10289: container-tools:ol8 security update (MODERATE)

7 месяцев назад
ubuntu логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
redhat логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
0%
Низкий
почти 4 года назад
msrc логотип
CVSS3: 7.5
0%
Низкий
9 месяцев назад
debian логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic fo ...

CVSS3: 7.5
0%
Низкий
почти 4 года назад
github логотип
GHSA-q2pw-fq43-w78v

Go before 1.15.12 and 1.16.x before 1.16.5 attempts to allocate excessive memory (issue 2 of 2).

CVSS3: 7.5
0%
Низкий
около 3 лет назад
fstec логотип
BDU:2022-00723

Уязвимость компонента math/big.Rat и метода unmarshaltext языка программирования Go, позволяющая нарушителю вызвать аварийный сбой и перезапуск устройства

CVSS3: 7.5
0%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2022-7955

ELSA-2022-7955: skopeo security and bug fix update (MODERATE)

больше 2 лет назад
ubuntu логотип
CVE-2021-4024

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-4024

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 4.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-4024

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-4024

A flaw was found in podman. The `podman machine` function (used to cre ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
2%
Низкий
8 месяцев назад
redhat логотип
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
2%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
2%
Низкий
8 месяцев назад
msrc логотип
CVSS3: 6.5
2%
Низкий
7 месяцев назад
debian логотип
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink tra ...

CVSS3: 6.5
2%
Низкий
8 месяцев назад
suse-cvrf логотип
openSUSE-SU-2021:2214-1

Security update for go1.15

почти 4 года назад
suse-cvrf логотип
openSUSE-SU-2021:2186-1

Security update for go1.16

почти 4 года назад

Уязвимостей на страницу