Show filters
815 Total Results
Displaying 431-440 of 815
Sort by:
Attacker Value
Unknown
CVE-2022-30630
Disclosure Date: August 10, 2022 (last updated November 08, 2023)
Uncontrolled recursion in Glob in io/fs before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a path which contains a large number of path separators.
0
Attacker Value
Unknown
CVE-2022-28131
Disclosure Date: August 10, 2022 (last updated November 08, 2023)
Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.
0
Attacker Value
Unknown
CVE-2022-32189
Disclosure Date: August 10, 2022 (last updated November 29, 2024)
A too-short encoded message can cause a panic in Float.GobDecode and Rat GobDecode in math/big in Go before 1.17.13 and 1.18.5, potentially allowing a denial of service.
0
Attacker Value
Unknown
CVE-2022-1705
Disclosure Date: August 10, 2022 (last updated November 08, 2023)
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the header as invalid.
0
Attacker Value
Unknown
CVE-2022-30629
Disclosure Date: August 10, 2022 (last updated November 08, 2023)
Non-random values for ticket_age_add in session tickets in crypto/tls before Go 1.17.11 and Go 1.18.3 allow an attacker that can observe TLS handshakes to correlate successive connections by comparing ticket ages during session resumption.
0
Attacker Value
Unknown
CVE-2022-37450
Disclosure Date: August 05, 2022 (last updated October 08, 2023)
Go Ethereum (aka geth) through 1.10.21 allows attackers to increase rewards by mining blocks in certain situations, and using a manipulation of time-difference values to achieve replacement of main-chain blocks, aka Riskless Uncle Making (RUM), as exploited in the wild in 2020 through 2022.
0
Attacker Value
Unknown
CVE-2022-2675
Disclosure Date: August 04, 2022 (last updated October 08, 2023)
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0.1.9 (using firmware version 0.1.35) can be powered down by an attacker within normal RF range without authentication. Other versions may be affected, such as the A1.
0
Attacker Value
Unknown
CVE-2022-35926
Disclosure Date: August 04, 2022 (last updated October 08, 2023)
Contiki-NG is an open-source, cross-platform operating system for IoT devices. Because of insufficient validation of IPv6 neighbor discovery options in Contiki-NG, attackers can send neighbor solicitation packets that trigger an out-of-bounds read. The problem exists in the module os/net/ipv6/uip-nd6.c, where memory read operations from the main packet buffer, <code>uip_buf</code>, are not checked if they go out of bounds. In particular, this problem can occur when attempting to read the 2-byte option header and the Source Link-Layer Address Option (SLLAO). This attack requires ipv6 be enabled for the network. The problem has been patched in the develop branch of Contiki-NG. The upcoming 4.8 release of Contiki-NG will include the patch.Users unable to upgrade may apply the patch in Contiki-NG PR #1654.
0
Attacker Value
Unknown
CVE-2022-31120
Disclosure Date: August 04, 2022 (last updated October 08, 2023)
Nextcloud server is an open source personal cloud solution. The audit log is used to get a full trail of the actions which has been incompletely populated. In affected versions federated share events were not properly logged which would allow brute force attacks to go unnoticed. This behavior exacerbates the impact of CVE-2022-31118. It is recommended that the Nextcloud Server is upgraded to 22.2.7, 23.0.4 or 24.0.0. There are no workarounds available.
0
Attacker Value
Unknown
CVE-2022-37315
Disclosure Date: August 01, 2022 (last updated October 08, 2023)
graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.
0