Логотип exploitDog
bind:"CVE-2024-7264"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-7264"

Количество 16

Количество 16

ubuntu логотип

CVE-2024-7264

больше 1 года назад

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-7264

больше 1 года назад

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-7264

больше 1 года назад

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-7264

около 1 года назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-7264

больше 1 года назад

libcurl's ASN1 parser code has the `GTime2str()` function, used for pa ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3080-2

около 1 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3080-1

около 1 года назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2938-1

около 1 года назад

Security update for curl

EPSS: Низкий
github логотип

GHSA-97c4-2w4v-c7r8

больше 1 года назад

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2024-05923

больше 1 года назад

Уязвимость функции GTime2str парсера ASN1 Parser библиотеки libcurl, позволяющая нарушителю вызвать октаз в обслуживании

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2784-1

около 1 года назад

Security update for curl

EPSS: Низкий
redos логотип

ROS-20240816-22

около 1 года назад

Уязвимость libcurl

CVSS3: 4.8
EPSS: Низкий
redos логотип

ROS-20240816-13

около 1 года назад

Уязвимость zlib

CVSS3: 4.8
EPSS: Низкий
redos логотип

ROS-20240816-02

около 1 года назад

Уязвимость curl

CVSS3: 4.8
EPSS: Низкий
oracle-oval логотип

ELSA-2025-1673

9 месяцев назад

ELSA-2025-1673: mysql:8.0 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-1671

9 месяцев назад

ELSA-2025-1671: mysql security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-7264

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
5%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-7264

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 5.3
5%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-7264

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
5%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 6.5
5%
Низкий
около 1 года назад
debian логотип
CVE-2024-7264

libcurl's ASN1 parser code has the `GTime2str()` function, used for pa ...

CVSS3: 6.5
5%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3080-2

Security update for curl

5%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3080-1

Security update for curl

5%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2938-1

Security update for curl

5%
Низкий
около 1 года назад
github логотип
GHSA-97c4-2w4v-c7r8

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
5%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-05923

Уязвимость функции GTime2str парсера ASN1 Parser библиотеки libcurl, позволяющая нарушителю вызвать октаз в обслуживании

CVSS3: 4.8
5%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:2784-1

Security update for curl

около 1 года назад
redos логотип
ROS-20240816-22

Уязвимость libcurl

CVSS3: 4.8
5%
Низкий
около 1 года назад
redos логотип
ROS-20240816-13

Уязвимость zlib

CVSS3: 4.8
5%
Низкий
около 1 года назад
redos логотип
ROS-20240816-02

Уязвимость curl

CVSS3: 4.8
5%
Низкий
около 1 года назад
oracle-oval логотип
ELSA-2025-1673

ELSA-2025-1673: mysql:8.0 security update (IMPORTANT)

9 месяцев назад
oracle-oval логотип
ELSA-2025-1671

ELSA-2025-1671: mysql security update (IMPORTANT)

9 месяцев назад

Уязвимостей на страницу