Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown
CVE-2024-9355
Disclosure Date: October 01, 2024 (last updated January 05, 2025)
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum. It is also possible to force a derived key to be all zeros instead of an unpredictable value. This may have follow-on implications for the Go TLS stack.
0
Attacker Value
Unknown
CVE-2024-1394
Disclosure Date: March 21, 2024 (last updated August 21, 2024)
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey and ctx. That function uses named return parameters to free pkey and ctx if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey and ctx will be nil inside the deferred function that should free them.
0
Attacker Value
Unknown
CVE-2023-1672
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.
0
Attacker Value
Unknown
CVE-2023-34736
Disclosure Date: June 28, 2023 (last updated February 25, 2025)
Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.
0
Attacker Value
Unknown
CVE-2021-32854
Disclosure Date: February 21, 2023 (last updated February 24, 2025)
textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There are no known patches.
0
Attacker Value
Unknown
CVE-2022-33977
Disclosure Date: July 26, 2022 (last updated February 24, 2025)
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.
0
Attacker Value
Unknown
CVE-2022-31471
Disclosure Date: July 26, 2022 (last updated February 24, 2025)
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.
0
Attacker Value
Unknown
CVE-2022-34981
Disclosure Date: July 22, 2022 (last updated October 07, 2023)
The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
0
Attacker Value
Unknown
CVE-2021-4076
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
0
Attacker Value
Unknown
CVE-2020-17494
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Untangle Firewall NG before 16.0 uses MD5 for passwords.
0