Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 26

Количество 26

oracle-oval логотип

ELSA-2022-17957

около 4 лет назад

ELSA-2022-17957: ol8addon security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2005-1

больше 4 лет назад

Security update for go1.18

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:2004-1

больше 4 лет назад

Security update for go1.17

EPSS: Низкий
altlinux логотип

ALT-PU-2022-2036

больше 4 лет назад

ALT-PU-2022-2036: package `golang` update to version 1.18.3-alt1

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2022-30269

около 4 лет назад

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVSS3: 8.8
EPSS: Низкий
altlinux логотип

ALT-PU-2022-2041

больше 4 лет назад

ALT-PU-2022-2041: package `golang` update to version 1.17.11-alt1.p10

CVSS3: 7.8
EPSS: Низкий
oracle-oval логотип

ELSA-2022-17956

около 4 лет назад

ELSA-2022-17956: go-toolset:ol8addon security update (IMPORTANT)

EPSS: Низкий
github логотип

GHSA-p4gj-rmqv-7h27

около 4 лет назад

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVSS3: 8.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:2312-1

больше 3 лет назад

Security update for go1.18-openssl

EPSS: Низкий
ubuntu логотип

CVE-2022-30634

около 4 лет назад

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-30634

около 4 лет назад

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-30634

около 1 года назад

Indefinite hang with large buffers on Windows in crypto/rand

EPSS: Низкий
debian логотип

CVE-2022-30634

около 4 лет назад

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 o ...

CVSS3: 7.5
EPSS: Низкий
altlinux логотип

ALT-PU-2022-2873

почти 4 года назад

ALT-PU-2022-2873: package `golang` update to version 1.18.7-alt1

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-vfh9-chgv-wfph

около 4 лет назад

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-29804

около 4 лет назад

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-29804

около 4 лет назад

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2022-29804

около 1 года назад

Path traversal via Clean on Windows in path/filepath

EPSS: Низкий
debian логотип

CVE-2022-29804

около 4 лет назад

Incorrect conversion of certain invalid paths to valid, absolute paths ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2022-30580

около 4 лет назад

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2022-17957

ELSA-2022-17957: ol8addon security update (IMPORTANT)

около 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:2005-1

Security update for go1.18

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:2004-1

Security update for go1.17

больше 4 лет назад
altlinux логотип
ALT-PU-2022-2036

ALT-PU-2022-2036: package `golang` update to version 1.18.3-alt1

CVSS3: 7.8
больше 4 лет назад
nvd логотип
CVE-2022-30269

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
altlinux логотип
ALT-PU-2022-2041

ALT-PU-2022-2041: package `golang` update to version 1.17.11-alt1.p10

CVSS3: 7.8
больше 4 лет назад
oracle-oval логотип
ELSA-2022-17956

ELSA-2022-17956: go-toolset:ol8addon security update (IMPORTANT)

около 4 лет назад
github логотип
GHSA-p4gj-rmqv-7h27

Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of the C toolkit, they are transferred and installed using SFTP/SSH. In each case, application images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVSS3: 8.8
0%
Низкий
около 4 лет назад
suse-cvrf логотип
SUSE-SU-2023:2312-1

Security update for go1.18-openssl

больше 3 лет назад
ubuntu логотип
CVE-2022-30634

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-30634

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
msrc логотип
CVE-2022-30634

Indefinite hang with large buffers on Windows in crypto/rand

2%
Низкий
около 1 года назад
debian логотип
CVE-2022-30634

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 o ...

CVSS3: 7.5
2%
Низкий
около 4 лет назад
altlinux логотип
ALT-PU-2022-2873

ALT-PU-2022-2873: package `golang` update to version 1.18.7-alt1

CVSS3: 9.8
почти 4 года назад
github логотип
GHSA-vfh9-chgv-wfph

Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-29804

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
nvd логотип
CVE-2022-29804

Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
msrc логотип
CVE-2022-29804

Path traversal via Clean on Windows in path/filepath

2%
Низкий
около 1 года назад
debian логотип
CVE-2022-29804

Incorrect conversion of certain invalid paths to valid, absolute paths ...

CVSS3: 7.5
2%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2022-30580

Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

CVSS3: 7.8
1%
Низкий
около 4 лет назад

Уязвимостей на страницу