Записи dfinity
5 опубликованных записей вендора dfinity.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 80 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-401 Missing Release of Memory after Effective Lifetime2
- CWE-20 Improper Input Validation1
- CWE-321 Use of Hard-coded Cryptographic Key1
- CWE-908 Use of Uninitialized Resource1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2024-1631Эксплойта нет | agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`dfinity · icp-js-core · CWE-321 | Критическая9,1 | — | 0,9 % | 20 февр. 2024 г. |
30Наблюдать | CVE-2023-6245Эксплойта нет | Infinite decoding loop through specially crafted payloaddfinity · candid · CWE-20 | Высокая7,5 | — | 1,2 % | 8 дек. 2023 г. |
30Наблюдать | CVE-2024-7884Эксплойта нет | Memory leak when calling a canister method via `ic_cdk::call`dfinity · canister developer kit for the internet computer · CWE-401 | Высокая7,5 | — | 0,7 % | 5 сент. 2024 г. |
30Наблюдать | CVE-2024-4435Эксплойта нет | BTreeMap memory leak when deallocating nodes with overflowsdfinity · stable structures · CWE-401 | Высокая7,5 | — | 0,5 % | 21 мая 2024 г. |
26Наблюдать | CVE-2024-11991Эксплойта нет | Uninitialized memory access in Motoko incremental garbage collectordfinity · motoko · CWE-908 | Средняя6,5 | — | 0,2 % | 9 дек. 2024 г. |
- CVE-2024-163136Наблюдать
agent-js: Insecure Key Generation in `Ed25519KeyIdentity.generate`
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %dfinity · icp-js-core20 февр. 2024 г.
- CVE-2023-624530Наблюдать
Infinite decoding loop through specially crafted payload
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dfinity · candid8 дек. 2023 г.
- CVE-2024-788430Наблюдать
Memory leak when calling a canister method via `ic_cdk::call`
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dfinity · canister developer kit for the internet computer5 сент. 2024 г.
- CVE-2024-443530Наблюдать
BTreeMap memory leak when deallocating nodes with overflows
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dfinity · stable structures21 мая 2024 г.
- CVE-2024-1199126Наблюдать
Uninitialized memory access in Motoko incremental garbage collector
СредняяCVSS 6,5Эксплойта нетEPSS 0 %dfinity · motoko9 дек. 2024 г.