Логотип exploitDog
bind:"CVE-2024-1394" OR bind:"CVE-2024-34156"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-1394" OR bind:"CVE-2024-34156"

Количество 85

Количество 85

rocky логотип

RLSA-2024:7262

9 месяцев назад

Important: osbuild-composer security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7262

9 месяцев назад

ELSA-2024-7262: osbuild-composer security update (IMPORTANT)

EPSS: Низкий
redhat логотип

CVE-2024-1394

около 1 года назад

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-1394

около 1 года назад

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-34156

10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2024-34156

10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-34156

10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-34156

10 месяцев назад

Calling Decoder.Decode on a message which contains deeply nested struc ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2024:4502

11 месяцев назад

Important: skopeo security update

EPSS: Низкий
rocky логотип

RLSA-2024:2569

около 1 года назад

Important: grafana-pcp security update

EPSS: Низкий
rocky логотип

RLSA-2024:1646

около 1 года назад

Important: grafana security and bug fix update

EPSS: Низкий
rocky логотип

RLSA-2024:1644

около 1 года назад

Important: grafana-pcp security and bug fix update

EPSS: Низкий
rocky логотип

RLSA-2024:1502

около 1 года назад

Important: grafana-pcp security update

EPSS: Низкий
github логотип

GHSA-78hx-gp6g-7mj6

около 1 года назад

Memory leaks in code encrypting and verifying RSA payloads

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-4762

11 месяцев назад

ELSA-2024-4762: runc security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4761

11 месяцев назад

ELSA-2024-4761: containernetworking-plugins security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4502

11 месяцев назад

ELSA-2024-4502: skopeo security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4379

12 месяцев назад

ELSA-2024-4379: gvisor-tap-vsock security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4378

12 месяцев назад

ELSA-2024-4378: podman security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-4371

12 месяцев назад

ELSA-2024-4371: buildah security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2024:7262

Important: osbuild-composer security update

9 месяцев назад
oracle-oval логотип
ELSA-2024-7262

ELSA-2024-7262: osbuild-composer security update (IMPORTANT)

9 месяцев назад
redhat логотип
CVE-2024-1394

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.

CVSS3: 7.5
1%
Низкий
около 1 года назад
nvd логотип
CVE-2024-1394

A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.

CVSS3: 7.5
1%
Низкий
около 1 года назад
ubuntu логотип
CVE-2024-34156

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
redhat логотип
CVE-2024-34156

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-34156

Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-34156

Calling Decoder.Decode on a message which contains deeply nested struc ...

CVSS3: 7.5
0%
Низкий
10 месяцев назад
rocky логотип
RLSA-2024:4502

Important: skopeo security update

1%
Низкий
11 месяцев назад
rocky логотип
RLSA-2024:2569

Important: grafana-pcp security update

1%
Низкий
около 1 года назад
rocky логотип
RLSA-2024:1646

Important: grafana security and bug fix update

1%
Низкий
около 1 года назад
rocky логотип
RLSA-2024:1644

Important: grafana-pcp security and bug fix update

1%
Низкий
около 1 года назад
rocky логотип
RLSA-2024:1502

Important: grafana-pcp security update

1%
Низкий
около 1 года назад
github логотип
GHSA-78hx-gp6g-7mj6

Memory leaks in code encrypting and verifying RSA payloads

CVSS3: 7.5
1%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2024-4762

ELSA-2024-4762: runc security update (IMPORTANT)

11 месяцев назад
oracle-oval логотип
ELSA-2024-4761

ELSA-2024-4761: containernetworking-plugins security update (IMPORTANT)

11 месяцев назад
oracle-oval логотип
ELSA-2024-4502

ELSA-2024-4502: skopeo security update (IMPORTANT)

11 месяцев назад
oracle-oval логотип
ELSA-2024-4379

ELSA-2024-4379: gvisor-tap-vsock security update (IMPORTANT)

12 месяцев назад
oracle-oval логотип
ELSA-2024-4378

ELSA-2024-4378: podman security update (IMPORTANT)

12 месяцев назад
oracle-oval логотип
ELSA-2024-4371

ELSA-2024-4371: buildah security update (IMPORTANT)

12 месяцев назад

Уязвимостей на страницу