Логотип exploitDog
bind:"CVE-2022-30269" OR bind:"CVE-2022-30634" OR bind:"CVE-2022-29804" OR bind:"CVE-2022-30580"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-30269" OR bind:"CVE-2022-30634" OR bind:"CVE-2022-29804" OR bind:"CVE-2022-30580"

Количество 21

Количество 21

oracle-oval логотип

ELSA-2022-17957

почти 3 года назад

ELSA-2022-17957: ol8addon security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2005-1

около 3 лет назад

Security update for go1.18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2004-1

около 3 лет назад

Security update for go1.17

EPSS: Низкий
nvd логотип

CVE-2022-30269

почти 3 года назад

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVSS3: 8.8
EPSS: Низкий
oracle-oval логотип

ELSA-2022-17956

почти 3 года назад

ELSA-2022-17956: go-toolset:ol8addon security update (IMPORTANT)

EPSS: Низкий
github логотип

GHSA-p4gj-rmqv-7h27

почти 3 года назад

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2312-1

около 2 лет назад

Security update for go1.18-openssl

EPSS: Низкий
ubuntu логотип

CVE-2022-30634

почти 3 года назад

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-30634

почти 3 года назад

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-30634

почти 3 года назад

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 o ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vfh9-chgv-wfph

почти 3 года назад

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-29804

почти 3 года назад

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-29804

почти 3 года назад

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-29804

почти 3 года назад

Incorrect conversion of certain invalid paths to valid, absolute paths ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-30580

почти 3 года назад

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2022-30580

почти 3 года назад

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2022-30580

почти 3 года назад

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVSS3: 7.8
EPSS: Низкий
msrc логотип

CVE-2022-30580

почти 3 года назад

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2022-30580

почти 3 года назад

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4r7w-gv7f-q74g

почти 3 года назад

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2022-17957

ELSA-2022-17957: ol8addon security update (IMPORTANT)

почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:2005-1

Security update for go1.18

около 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:2004-1

Security update for go1.17

около 3 лет назад
nvd логотип
CVE-2022-30269

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
oracle-oval логотип
ELSA-2022-17956

ELSA-2022-17956: go-toolset:ol8addon security update (IMPORTANT)

почти 3 года назад
github логотип
GHSA-p4gj-rmqv-7h27

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2023:2312-1

Security update for go1.18-openssl

около 2 лет назад
ubuntu логотип
CVE-2022-30634

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-30634

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-30634

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 o ...

CVSS3: 7.5
0%
Низкий
почти 3 года назад
github логотип
GHSA-vfh9-chgv-wfph

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-29804

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-29804

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-29804

Incorrect conversion of certain invalid paths to valid, absolute paths ...

CVSS3: 7.5
0%
Низкий
почти 3 года назад
ubuntu логотип
CVE-2022-30580

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
redhat логотип
CVE-2022-30580

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2022-30580

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVSS3: 7.8
0%
Низкий
почти 3 года назад
msrc логотип
CVSS3: 7.8
0%
Низкий
почти 3 года назад
debian логотип
CVE-2022-30580

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 ...

CVSS3: 7.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-4r7w-gv7f-q74g

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
0%
Низкий
почти 3 года назад

Уязвимостей на страницу