Search CVE reports
131 – 140 of 1291 results
CVE-2024-22189
Medium priorityquic-go is an implementation of the QUIC protocol in Go. Prior to version 0.42.0, an attacker can cause its peer to run out of memory sending a large number of `NEW_CONNECTION_ID` frames that retire old connection IDs....
1 affected package
golang-github-lucas-clemente-quic-go
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
golang-github-lucas-clemente-quic-go | Not affected | Needs evaluation | Not in release | — | — |
CVE-2024-2818
Medium priorityAn issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. It was possible for an attacker to cause a denial...
1 affected package
gitlab
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
gitlab | Not in release | Not in release | Not in release | — | Ignored |
CVE-2023-6371
Medium priorityAn issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a...
1 affected package
gitlab
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
gitlab | Not in release | Not in release | Not in release | — | Ignored |
CVE-2024-1753
Medium priorityA flaw was found in Buildah (and subsequently Podman Build) which allows containers to mount arbitrary locations on the host filesystem into build containers. A malicious Containerfile can use a dummy image with a symbolic link to...
1 affected package
golang-github-containers-buildah
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
golang-github-containers-buildah | Needs evaluation | Needs evaluation | Not in release | — | — |
CVE-2024-28180
Medium priorityPackage jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed...
1 affected package
golang-github-go-jose-go-jose
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
golang-github-go-jose-go-jose | Needs evaluation | Not in release | Not in release | — | — |
CVE-2024-1299
Medium priorityA privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for a user with custom role of `manage_group_access_tokens` to rotate group access...
1 affected package
gitlab
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
gitlab | Not in release | Not in release | Not in release | — | Ignored |
CVE-2024-0199
Medium priorityAn authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an...
1 affected package
gitlab
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
gitlab | Not in release | Not in release | Not in release | — | Ignored |
CVE-2024-27304
Medium prioritypgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if an attacker can cause a single query or bind message to exceed 4 GB in size. An integer overflow in the calculated message size can cause the one large...
2 affected packages
golang-github-jackc-pgproto3, golang-github-jackc-pgx
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
golang-github-jackc-pgproto3 | Needs evaluation | Not in release | Not in release | — | — |
golang-github-jackc-pgx | Needs evaluation | Needs evaluation | Not in release | — | — |
CVE-2024-27289
Medium prioritypgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL injection can occur when all of the following conditions are met: the non-default simple protocol is used; a placeholder for a numeric value must be...
1 affected package
golang-github-jackc-pgx
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
golang-github-jackc-pgx | Needs evaluation | Needs evaluation | Not in release | — | — |
CVE-2023-50658
Medium priorityThe jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
1 affected package
golang-github-dvsekhvalnov-jose2go
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
golang-github-dvsekhvalnov-jose2go | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation | Needs evaluation |