alexzorin

3 exploits Active since Mar 2017
CVE-2021-34558 NOMISEC MEDIUM WORKING POC
GO < 1.15.14 - Improper Certificate Validation
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.
46 stars
CVSS 6.5
CVE-2018-16875 NOMISEC MEDIUM WORKING POC
Go <1.10.6/1.11.x - DoS
The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.
9 stars
CVSS 5.9
CVE-2017-2636 NOMISEC HIGH WRITEUP
Linux Kernel < 3.2.87 - Race Condition
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
1 stars
CVSS 7.0