Логотип exploitDog
bind:CVE-2024-7264
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-7264

Количество 15

Количество 15

ubuntu логотип

CVE-2024-7264

11 месяцев назад

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-7264

11 месяцев назад

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-7264

11 месяцев назад

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
EPSS: Низкий
msrc логотип

CVE-2024-7264

8 месяцев назад

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-7264

11 месяцев назад

libcurl's ASN1 parser code has the `GTime2str()` function, used for pa ...

CVSS3: 6.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3080-2

9 месяцев назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:3080-1

10 месяцев назад

Security update for curl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2938-1

10 месяцев назад

Security update for curl

EPSS: Низкий
github логотип

GHSA-97c4-2w4v-c7r8

11 месяцев назад

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2024-05923

11 месяцев назад

Уязвимость функции GTime2str парсера ASN1 Parser библиотеки libcurl, позволяющая нарушителю вызвать октаз в обслуживании

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:2784-1

11 месяцев назад

Security update for curl

EPSS: Низкий
redos логотип

ROS-20240816-13

10 месяцев назад

Уязвимость zlib

CVSS3: 4.8
EPSS: Низкий
redos логотип

ROS-20240816-02

10 месяцев назад

Уязвимость curl

CVSS3: 4.8
EPSS: Низкий
oracle-oval логотип

ELSA-2025-1673

4 месяца назад

ELSA-2025-1673: mysql:8.0 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2025-1671

4 месяца назад

ELSA-2025-1671: mysql security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-7264

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
3%
Низкий
11 месяцев назад
redhat логотип
CVE-2024-7264

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 5.3
3%
Низкий
11 месяцев назад
nvd логотип
CVE-2024-7264

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
3%
Низкий
11 месяцев назад
msrc логотип
CVSS3: 6.5
3%
Низкий
8 месяцев назад
debian логотип
CVE-2024-7264

libcurl's ASN1 parser code has the `GTime2str()` function, used for pa ...

CVSS3: 6.5
3%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3080-2

Security update for curl

3%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:3080-1

Security update for curl

3%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:2938-1

Security update for curl

3%
Низкий
10 месяцев назад
github логотип
GHSA-97c4-2w4v-c7r8

libcurl's ASN1 parser code has the `GTime2str()` function, used for parsing an ASN.1 Generalized Time field. If given an syntactically incorrect field, the parser might end up using -1 for the length of the *time fraction*, leading to a `strlen()` getting performed on a pointer to a heap buffer area that is not (purposely) null terminated. This flaw most likely leads to a crash, but can also lead to heap contents getting returned to the application when [CURLINFO_CERTINFO](https://curl.se/libcurl/c/CURLINFO_CERTINFO.html) is used.

CVSS3: 6.5
3%
Низкий
11 месяцев назад
fstec логотип
BDU:2024-05923

Уязвимость функции GTime2str парсера ASN1 Parser библиотеки libcurl, позволяющая нарушителю вызвать октаз в обслуживании

CVSS3: 4.8
3%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2024:2784-1

Security update for curl

11 месяцев назад
redos логотип
ROS-20240816-13

Уязвимость zlib

CVSS3: 4.8
3%
Низкий
10 месяцев назад
redos логотип
ROS-20240816-02

Уязвимость curl

CVSS3: 4.8
3%
Низкий
10 месяцев назад
oracle-oval логотип
ELSA-2025-1673

ELSA-2025-1673: mysql:8.0 security update (IMPORTANT)

4 месяца назад
oracle-oval логотип
ELSA-2025-1671

ELSA-2025-1671: mysql security update (IMPORTANT)

4 месяца назад

Уязвимостей на страницу