Записи protocol
24 опубликованных записей вендора protocol.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 91,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption7
- CWE-190 Integer Overflow or Wraparound3
- CWE-770 Allocation of Resources Without Limits or Throttling3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-116 Improper Encoding or Escaping of Output1
- CWE-281 Improper Preservation of Permissions1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2020-12821Эксплойта нет | Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.protocol · gossipsub | Критическая9,8 | — | 1,9 % | 7 июл. 2020 г. |
35Наблюдать | CVE-2020-26283Эксплойта нет | Control character injection in console outputprotocol · go-ipfs · CWE-116 | Высокая8,8 | — | 1,5 % | 24 мар. 2021 г. |
34Наблюдать | CVE-2026-31814Эксплойта нет | Yamux remote Panic via malformed WindowUpdate creditprotocol · yamux · CWE-190 | Высокая8,7 | — | 0,6 % | 13 мар. 2026 г. |
34Наблюдать | CVE-2026-32314Эксплойта нет | Yamux remote Panic via malformed Data frame with SYN set and len = 262145protocol · yamux · CWE-248 | Высокая8,7 | — | 0,6 % | 16 мар. 2026 г. |
34Наблюдать | CVE-2026-33040Эксплойта нет | libp2p-rust: Gossipsub PRUNE.backoff Duration Overflowprotocol · libp2p-gossipsub · CWE-190 | Высокая8,7 | — | 0,5 % | 20 мар. 2026 г. |
33Наблюдать | CVE-2020-26279Эксплойта нет | go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem.protocol · go-ipfs · CWE-22 | Высокая8,1 | — | 1,7 % | 24 мар. 2021 г. |
32Наблюдать | CVE-2026-34219Эксплойта нет | libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflowprotocol · libp2p-gossipsub · CWE-190 | Высокая8,2 | — | 0,5 % | 31 мар. 2026 г. |
32Наблюдать | CVE-2026-35457Эксплойта нет | libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustionprotocol · libp2p · CWE-770 | Высокая8,2 | — | 0,4 % | 7 апр. 2026 г. |
30Наблюдать | CVE-2020-35909Эксплойта нет | An issue was discovered in the multihash crate before 0.11.3 for Rust.protocol · multihash | Высокая7,5 | — | 1,4 % | 31 дек. 2020 г. |
30Наблюдать | CVE-2022-23495Эксплойта нет | ProtoNode may be modified such that common method calls may panic in ipfs/go-merkledagprotocol · go-merkledag · CWE-755 | Высокая7,5 | — | 1,3 % | 8 дек. 2022 г. |
30Наблюдать | CVE-2020-10937Эксплойта нет | An issue was discovered in IPFS (aka go-ipfs) 0.4.23.protocol · ipfs | Высокая7,5 | — | 1,2 % | 2 нояб. 2020 г. |
30Наблюдать | CVE-2023-22460Эксплойта нет | go-ipld-prime json codec may panic if asked to encode bytesprotocol · go-ipld-prime · CWE-20 | Высокая7,5 | — | 1,1 % | 4 янв. 2023 г. |
30Наблюдать | CVE-2022-23492Эксплойта нет | go-libp2p denial of service vulnerability from lack of resource managementprotocol · libp2p · CWE-400 | Высокая7,5 | — | 1,0 % | 7 дек. 2022 г. |
30Наблюдать | CVE-2023-40583Эксплойта нет | libp2p nodes vulnerable to OOM attackprotocol · libp2p · CWE-400 | Высокая7,5 | — | 1,0 % | 25 авг. 2023 г. |
30Наблюдать | CVE-2023-23626Эксплойта нет | Denial of service when feeding malformed size arguments in go-bitfieldprotocol · go-bitfield · CWE-754 | Высокая7,5 | — | 0,9 % | 9 февр. 2023 г. |
30Наблюдать | CVE-2023-23631Эксплойта нет | HAMT Decoding Panics in github.com/ipfs/go-unixfsnodeprotocol · go-unixfsnode · CWE-400 | Высокая7,5 | — | 0,9 % | 9 февр. 2023 г. |
30Наблюдать | CVE-2023-25568Эксплойта нет | Boxo bitswap/server: DOS unbounded persistent memory leakprotocol · boxo · CWE-400 | Высокая7,5 | — | 0,9 % | 10 мая 2023 г. |
30Наблюдать | CVE-2022-2584Эксплойта нет | Panic when decoding invalid blocks in github.com/ipld/go-codec-dagpbprotocol · go-codec-dagpb · CWE-119 | Высокая7,5 | — | 0,7 % | 27 дек. 2022 г. |
30Наблюдать | CVE-2022-23487Эксплойта нет | libp2p denial of service vulnerability from lack of resource managementprotocol · libp2p · CWE-400 | Высокая7,5 | — | 0,7 % | 7 дек. 2022 г. |
30Наблюдать | CVE-2022-23486Эксплойта нет | libp2p-rust denial of service vulnerability from lack of resource managementprotocol · libp2p · CWE-400 | Высокая7,5 | — | 0,7 % | 7 дек. 2022 г. |
30Наблюдать | CVE-2023-23625Эксплойта нет | Denial of service in HAMT Decoding in go-unixfsprotocol · go-unixfs · CWE-400 | Высокая7,5 | — | 0,7 % | 9 февр. 2023 г. |
30Наблюдать | CVE-2026-35405Эксплойта нет | libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous serversprotocol · libp2p · CWE-770 | Высокая7,5 | — | 0,5 % | 7 апр. 2026 г. |
24Наблюдать | CVE-2026-35480Эксплойта нет | go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headersprotocol · go-ipld-prime · CWE-770 | Средняя6,2 | — | 0,2 % | 7 апр. 2026 г. |
21Наблюдать | CVE-2022-47547Эксплойта нет | GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though itprotocol · gossipsub · CWE-281 | Средняя5,3 | — | 0,5 % | 19 дек. 2022 г. |
- CVE-2020-1282140В плане
Gossipsub 1.0 does not properly resist invalid message spam, such as an eclipse attack or a sybil attack.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %protocol · gossipsub7 июл. 2020 г.
- CVE-2020-2628335Наблюдать
Control character injection in console output
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %protocol · go-ipfs24 мар. 2021 г.
- CVE-2026-3181434Наблюдать
Yamux remote Panic via malformed WindowUpdate credit
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %protocol · yamux13 мар. 2026 г.
- CVE-2026-3231434Наблюдать
Yamux remote Panic via malformed Data frame with SYN set and len = 262145
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %protocol · yamux16 мар. 2026 г.
- CVE-2026-3304034Наблюдать
libp2p-rust: Gossipsub PRUNE.backoff Duration Overflow
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %protocol · libp2p-gossipsub20 мар. 2026 г.
- CVE-2020-2627933Наблюдать
go-ipfs is an open-source golang implementation of IPFS which is a global, versioned, peer-to-peer filesystem.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %protocol · go-ipfs24 мар. 2021 г.
- CVE-2026-3421932Наблюдать
libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %protocol · libp2p-gossipsub31 мар. 2026 г.
- CVE-2026-3545732Наблюдать
libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %protocol · libp2p7 апр. 2026 г.
- CVE-2020-3590930Наблюдать
An issue was discovered in the multihash crate before 0.11.3 for Rust.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · multihash31 дек. 2020 г.
- CVE-2022-2349530Наблюдать
ProtoNode may be modified such that common method calls may panic in ipfs/go-merkledag
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · go-merkledag8 дек. 2022 г.
- CVE-2020-1093730Наблюдать
An issue was discovered in IPFS (aka go-ipfs) 0.4.23.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · ipfs2 нояб. 2020 г.
- CVE-2023-2246030Наблюдать
go-ipld-prime json codec may panic if asked to encode bytes
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · go-ipld-prime4 янв. 2023 г.
- CVE-2022-2349230Наблюдать
go-libp2p denial of service vulnerability from lack of resource management
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · libp2p7 дек. 2022 г.
- CVE-2023-4058330Наблюдать
libp2p nodes vulnerable to OOM attack
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · libp2p25 авг. 2023 г.
- CVE-2023-2362630Наблюдать
Denial of service when feeding malformed size arguments in go-bitfield
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · go-bitfield9 февр. 2023 г.
- CVE-2023-2363130Наблюдать
HAMT Decoding Panics in github.com/ipfs/go-unixfsnode
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · go-unixfsnode9 февр. 2023 г.
- CVE-2023-2556830Наблюдать
Boxo bitswap/server: DOS unbounded persistent memory leak
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · boxo10 мая 2023 г.
- CVE-2022-258430Наблюдать
Panic when decoding invalid blocks in github.com/ipld/go-codec-dagpb
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · go-codec-dagpb27 дек. 2022 г.
- CVE-2022-2348730Наблюдать
libp2p denial of service vulnerability from lack of resource management
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · libp2p7 дек. 2022 г.
- CVE-2022-2348630Наблюдать
libp2p-rust denial of service vulnerability from lack of resource management
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · libp2p7 дек. 2022 г.
- CVE-2023-2362530Наблюдать
Denial of service in HAMT Decoding in go-unixfs
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %protocol · go-unixfs9 февр. 2023 г.
- CVE-2026-3540530Наблюдать
libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvous servers
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %protocol · libp2p7 апр. 2026 г.
- CVE-2026-3548024Наблюдать
go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers
СредняяCVSS 6,2Эксплойта нетEPSS 0 %protocol · go-ipld-prime7 апр. 2026 г.
- CVE-2022-4754721Наблюдать
GossipSub 1.1, as used for Ethereum 2.0, allows a peer to maintain a positive score (and thus not be pruned from the network) even though it
СредняяCVSS 5,3Эксплойта нетEPSS 1 %protocol · gossipsub19 дек. 2022 г.