Количество 24
Количество 24

RLSA-2024:8678
Important: grafana security update

RLSA-2024:8327
Important: grafana security update
ELSA-2024-8678
ELSA-2024-8678: grafana security update (IMPORTANT)
ELSA-2024-8327
ELSA-2024-8327: grafana security update (IMPORTANT)

CVE-2024-47875
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

CVE-2024-47875
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

CVE-2024-47875
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.
CVE-2024-47875
DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for H ...

CVE-2024-9355
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.

CVE-2024-9355
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.

CVE-2024-9355
GHSA-gx9m-whjm-85jf
DOMpurify has a nesting-based mXSS

BDU:2024-08024
Уязвимость JavaScript-библиотеки для безопасной очистки и защиты HTML-кода DOMPurify, связанная с недостатками проверки входных данных, содержащих признаки XSS-атаки, позволяющая нарушителю осуществить межсайтовую сценарную атаку

RLSA-2024:8847
Moderate: grafana-pcp security update

RLSA-2024:7550
Moderate: golang security update
GHSA-3h3x-2hwv-hr52
Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability
ELSA-2024-8847
ELSA-2024-8847: grafana-pcp security update (MODERATE)
ELSA-2024-7550
ELSA-2024-7550: golang security update (MODERATE)
ELSA-2024-7502
ELSA-2024-7502: go-toolset:ol8 security update (MODERATE)

ROS-20241209-04
Уязвимость grafana
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | RLSA-2024:8678 Important: grafana security update | 9 месяцев назад | ||
![]() | RLSA-2024:8327 Important: grafana security update | 9 месяцев назад | ||
ELSA-2024-8678 ELSA-2024-8678: grafana security update (IMPORTANT) | 9 месяцев назад | |||
ELSA-2024-8327 ELSA-2024-8327: grafana security update (IMPORTANT) | 10 месяцев назад | |||
![]() | CVE-2024-47875 DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. | CVSS3: 10 | 0% Низкий | 10 месяцев назад |
![]() | CVE-2024-47875 DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. | CVSS3: 8 | 0% Низкий | 10 месяцев назад |
![]() | CVE-2024-47875 DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3. | CVSS3: 10 | 0% Низкий | 10 месяцев назад |
CVE-2024-47875 DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for H ... | CVSS3: 10 | 0% Низкий | 10 месяцев назад | |
![]() | CVE-2024-9355 A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад |
![]() | CVE-2024-9355 A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад |
![]() | CVSS3: 6.5 | 0% Низкий | 24 дня назад | |
GHSA-gx9m-whjm-85jf DOMpurify has a nesting-based mXSS | CVSS3: 10 | 0% Низкий | 10 месяцев назад | |
![]() | BDU:2024-08024 Уязвимость JavaScript-библиотеки для безопасной очистки и защиты HTML-кода DOMPurify, связанная с недостатками проверки входных данных, содержащих признаки XSS-атаки, позволяющая нарушителю осуществить межсайтовую сценарную атаку | CVSS3: 10 | 0% Низкий | 10 месяцев назад |
![]() | RLSA-2024:8847 Moderate: grafana-pcp security update | 0% Низкий | 9 месяцев назад | |
![]() | RLSA-2024:7550 Moderate: golang security update | 0% Низкий | 9 месяцев назад | |
GHSA-3h3x-2hwv-hr52 Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
ELSA-2024-8847 ELSA-2024-8847: grafana-pcp security update (MODERATE) | 9 месяцев назад | |||
ELSA-2024-7550 ELSA-2024-7550: golang security update (MODERATE) | 10 месяцев назад | |||
ELSA-2024-7502 ELSA-2024-7502: go-toolset:ol8 security update (MODERATE) | 10 месяцев назад | |||
![]() | ROS-20241209-04 Уязвимость grafana | CVSS3: 10 | 0% Низкий | 8 месяцев назад |
Уязвимостей на страницу