Логотип exploitDog
bind:"CVE-2024-9355" OR bind:"CVE-2024-47875"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2024-9355" OR bind:"CVE-2024-47875"

Количество 24

Количество 24

rocky логотип

RLSA-2024:8678

9 месяцев назад

Important: grafana security update

EPSS: Низкий
rocky логотип

RLSA-2024:8327

9 месяцев назад

Important: grafana security update

EPSS: Низкий
oracle-oval логотип

ELSA-2024-8678

9 месяцев назад

ELSA-2024-8678: grafana security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-8327

10 месяцев назад

ELSA-2024-8327: grafana security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2024-47875

10 месяцев назад

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

CVSS3: 10
EPSS: Низкий
redhat логотип

CVE-2024-47875

10 месяцев назад

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2024-47875

10 месяцев назад

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2024-47875

10 месяцев назад

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for H ...

CVSS3: 10
EPSS: Низкий
redhat логотип

CVE-2024-9355

10 месяцев назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-9355

10 месяцев назад

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-9355

24 дня назад

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gx9m-whjm-85jf

10 месяцев назад

DOMpurify has a nesting-based mXSS

CVSS3: 10
EPSS: Низкий
fstec логотип

BDU:2024-08024

10 месяцев назад

Уязвимость JavaScript-библиотеки для безопасной очистки и защиты HTML-кода DOMPurify, связанная с недостатками проверки входных данных, содержащих признаки XSS-атаки, позволяющая нарушителю осуществить межсайтовую сценарную атаку

CVSS3: 10
EPSS: Низкий
rocky логотип

RLSA-2024:8847

9 месяцев назад

Moderate: grafana-pcp security update

EPSS: Низкий
rocky логотип

RLSA-2024:7550

9 месяцев назад

Moderate: golang security update

EPSS: Низкий
github логотип

GHSA-3h3x-2hwv-hr52

10 месяцев назад

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
EPSS: Низкий
oracle-oval логотип

ELSA-2024-8847

9 месяцев назад

ELSA-2024-8847: grafana-pcp security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7550

10 месяцев назад

ELSA-2024-7550: golang security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-7502

10 месяцев назад

ELSA-2024-7502: go-toolset:ol8 security update (MODERATE)

EPSS: Низкий
redos логотип

ROS-20241209-04

8 месяцев назад

Уязвимость grafana

CVSS3: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2024:8678

Important: grafana security update

9 месяцев назад
rocky логотип
RLSA-2024:8327

Important: grafana security update

9 месяцев назад
oracle-oval логотип
ELSA-2024-8678

ELSA-2024-8678: grafana security update (IMPORTANT)

9 месяцев назад
oracle-oval логотип
ELSA-2024-8327

ELSA-2024-8327: grafana security update (IMPORTANT)

10 месяцев назад
ubuntu логотип
CVE-2024-47875

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

CVSS3: 10
0%
Низкий
10 месяцев назад
redhat логотип
CVE-2024-47875

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

CVSS3: 8
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-47875

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMpurify was vulnerable to nesting-based mXSS. This vulnerability is fixed in 2.5.0 and 3.1.3.

CVSS3: 10
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-47875

DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for H ...

CVSS3: 10
0%
Низкий
10 месяцев назад
redhat логотип
CVE-2024-9355

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-9355

A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
msrc логотип
CVSS3: 6.5
0%
Низкий
24 дня назад
github логотип
GHSA-gx9m-whjm-85jf

DOMpurify has a nesting-based mXSS

CVSS3: 10
0%
Низкий
10 месяцев назад
fstec логотип
BDU:2024-08024

Уязвимость JavaScript-библиотеки для безопасной очистки и защиты HTML-кода DOMPurify, связанная с недостатками проверки входных данных, содержащих признаки XSS-атаки, позволяющая нарушителю осуществить межсайтовую сценарную атаку

CVSS3: 10
0%
Низкий
10 месяцев назад
rocky логотип
RLSA-2024:8847

Moderate: grafana-pcp security update

0%
Низкий
9 месяцев назад
rocky логотип
RLSA-2024:7550

Moderate: golang security update

0%
Низкий
9 месяцев назад
github логотип
GHSA-3h3x-2hwv-hr52

Golang FIPS OpenSSL has a Use of Uninitialized Variable vulnerability

CVSS3: 6.5
0%
Низкий
10 месяцев назад
oracle-oval логотип
ELSA-2024-8847

ELSA-2024-8847: grafana-pcp security update (MODERATE)

9 месяцев назад
oracle-oval логотип
ELSA-2024-7550

ELSA-2024-7550: golang security update (MODERATE)

10 месяцев назад
oracle-oval логотип
ELSA-2024-7502

ELSA-2024-7502: go-toolset:ol8 security update (MODERATE)

10 месяцев назад
redos логотип
ROS-20241209-04

Уязвимость grafana

CVSS3: 10
0%
Низкий
8 месяцев назад

Уязвимостей на страницу