Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 51

Количество 51

rocky логотип

RLSA-2024:10289

больше 1 года назад

Moderate: container-tools:rhel8 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-10289

больше 1 года назад

ELSA-2024-10289: container-tools:ol8 security update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-33198

почти 5 лет назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2021-33198

больше 5 лет назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2021-33198

почти 5 лет назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2021-33198

почти 2 года назад

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2021-33198

почти 5 лет назад

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic fo ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q2pw-fq43-w78v

около 4 лет назад

Go before 1.15.12 and 1.16.x before 1.16.5 attempts to allocate excessive memory (issue 2 of 2).

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2022-00723

почти 5 лет назад

Уязвимость компонента math/big.Rat и метода unmarshaltext языка программирования Go, позволяющая нарушителю вызвать аварийный сбой и перезапуск устройства

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2022-7955

больше 3 лет назад

ELSA-2022-7955: skopeo security and bug fix update (MODERATE)

EPSS: Низкий
ubuntu логотип

CVE-2021-4024

больше 4 лет назад

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2021-4024

больше 4 лет назад

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2021-4024

больше 4 лет назад

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-4024

больше 4 лет назад

A flaw was found in podman. The `podman machine` function (used to cre ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-9676

больше 1 года назад

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-9676

больше 1 года назад

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-9676

больше 1 года назад

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-9676

больше 1 года назад

Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-9676

больше 1 года назад

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink tra ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2021:2214-1

почти 5 лет назад

Security update for go1.15

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2024:10289

Moderate: container-tools:rhel8 security update

больше 1 года назад
oracle-oval логотип
ELSA-2024-10289

ELSA-2024-10289: container-tools:ol8 security update (MODERATE)

больше 1 года назад
ubuntu логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
redhat логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
3%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic for a large exponent to the math/big.Rat SetString or UnmarshalText method.

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
msrc логотип
CVSS3: 7.5
3%
Низкий
почти 2 года назад
debian логотип
CVE-2021-33198

In Go before 1.15.13 and 1.16.x before 1.16.5, there can be a panic fo ...

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
github логотип
GHSA-q2pw-fq43-w78v

Go before 1.15.12 and 1.16.x before 1.16.5 attempts to allocate excessive memory (issue 2 of 2).

CVSS3: 7.5
3%
Низкий
около 4 лет назад
fstec логотип
BDU:2022-00723

Уязвимость компонента math/big.Rat и метода unmarshaltext языка программирования Go, позволяющая нарушителю вызвать аварийный сбой и перезапуск устройства

CVSS3: 7.5
3%
Низкий
почти 5 лет назад
oracle-oval логотип
ELSA-2022-7955

ELSA-2022-7955: skopeo security and bug fix update (MODERATE)

больше 3 лет назад
ubuntu логотип
CVE-2021-4024

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
redhat логотип
CVE-2021-4024

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 4.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-4024

A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-4024

A flaw was found in podman. The `podman machine` function (used to cre ...

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in Podman and Buildah). The containers/storage library will read /etc/passwd inside the container, but does not properly validate if that file is a symlink, which can be used to cause the library to read an arbitrary file on the host.

CVSS3: 6.5
1%
Низкий
больше 1 года назад
msrc логотип
CVE-2024-9676

Podman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)

CVSS3: 6.5
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9676

A vulnerability was found in Podman, Buildah, and CRI-O. A symlink tra ...

CVSS3: 6.5
1%
Низкий
больше 1 года назад
suse-cvrf логотип
openSUSE-SU-2021:2214-1

Security update for go1.15

почти 5 лет назад

Уязвимостей на страницу