gorillatoolkit records
3 published records for vendor gorillatoolkit.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-190 Integer Overflow or Wraparound1
- CWE-346 Origin Validation Error1
- CWE-770 Allocation of Resources Without Limits or Throttling1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2017-20146No exploit | Improper access control in github.com/gorilla/handlersgorillatoolkit · handlers · CWE-346 | Critical9.8 | — | 0.7% | Dec 27, 2022 |
31Monitor | CVE-2020-27813No exploit | An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection.gorillatoolkit · websocket · CWE-190 | High7.5 | — | 2.1% | Dec 1, 2020 |
30Monitor | CVE-2024-37298No exploit | Potential memory exhaustion attack due to sparse slice deserializationgorilla · schema · CWE-770 | High7.5 | — | 1.1% | Jul 1, 2024 |
- CVE-2017-2014639Monitor
Improper access control in github.com/gorilla/handlers
CriticalCVSS 9.8No exploitEPSS 1%gorillatoolkit · handlersDec 27, 2022
- CVE-2020-2781331Monitor
An integer overflow vulnerability exists with the length of websocket frames received via a websocket connection.
HighCVSS 7.5No exploitEPSS 2%gorillatoolkit · websocketDec 1, 2020
- CVE-2024-3729830Monitor
Potential memory exhaustion attack due to sparse slice deserialization
HighCVSS 7.5No exploitEPSS 1%gorilla · schemaJul 1, 2024