Show filters
18 Total Results
Displaying 1-10 of 18
Sort by:
Attacker Value
Unknown

CVE-2024-9355

Disclosure Date: October 01, 2024 (last updated January 05, 2025)
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.
0
Attacker Value
Unknown

CVE-2024-1394

Disclosure Date: March 21, 2024 (last updated August 21, 2024)
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs​. The memory leak happens in github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​ and ctx​. That function uses named return parameters to free pkey​ and ctx​ if there is an error initializing the context or setting the different properties. All return statements related to error cases follow the "return nil, nil, fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred function that should free them.
0
Attacker Value
Unknown

CVE-2023-1672

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.
Attacker Value
Unknown

CVE-2023-34736

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.
Attacker Value
Unknown

CVE-2021-32854

Disclosure Date: February 21, 2023 (last updated February 24, 2025)
textAngular is a text editor for Angular.js. Version 1.5.16 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. There are no known patches.
Attacker Value
Unknown

CVE-2022-33977

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this vulnerability, a remote unauthenticated attacker may cause a denial-of-service (DoS) condition on the server where the product is running.
Attacker Value
Unknown

CVE-2022-31471

Disclosure Date: July 26, 2022 (last updated February 24, 2025)
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vulnerability, a remote unauthenticated attacker may read the contents of local files.
Attacker Value
Unknown

CVE-2022-34981

Disclosure Date: July 22, 2022 (last updated October 07, 2023)
The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party.
Attacker Value
Unknown

CVE-2021-4076

Disclosure Date: March 02, 2022 (last updated February 23, 2025)
A flaw exists in tang, a network-based cryptographic binding server, which could result in leak of private keys.
Attacker Value
Unknown

CVE-2020-17494

Disclosure Date: November 12, 2020 (last updated February 22, 2025)
Untangle Firewall NG before 16.0 uses MD5 for passwords.