CVE-2024-32874 – In Frigate, Malicious Long Unicode filenames may cause a Multiple Application-level Denial of Service
https://notcve.org/view.php?id=CVE-2024-32874
Below 0.13.2 Release, when uploading a file or retrieving the filename, a user may intentionally use a large Unicode filename which would lead to a application-level denial of service. • https://github.com/blakeblackshear/frigate/commit/cc851555e4029647986dccc8b8ecf54afee31442 https://github.com/blakeblackshear/frigate/security/advisories/GHSA-w4h6-9wrp-v5jq • CWE-770: Allocation of Resources Without Limits or Throttling •
CVE-2024-32672
https://notcve.org/view.php?id=CVE-2024-32672
A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via crafted input. This issue affects Escargot: 4.0.0. • https://github.com/Samsung/escargot/pull/1322 • CWE-20: Improper Input Validation CWE-787: Out-of-bounds Write •
CVE-2023-6682 – Inefficient Regular Expression Complexity in GitLab
https://notcve.org/view.php?id=CVE-2023-6682
A problem with the processing logic for Discord Integrations Chat Messages can lead to a regular expression DoS attack on the server. ... Un problema con la lógica de procesamiento de los mensajes de chat de Discord Integrations puede provocar un ataque DoS de expresión regular en el servidor. • https://gitlab.com/gitlab-org/gitlab/-/issues/434821 https://hackerone.com/reports/2269012 • CWE-400: Uncontrolled Resource Consumption CWE-1333: Inefficient Regular Expression Complexity •
CVE-2023-6688 – Inefficient Regular Expression Complexity in GitLab
https://notcve.org/view.php?id=CVE-2023-6688
A problem with the processing logic for Google Chat Messages integration may lead to a regular expression DoS attack on the server. ... Un problema con la lógica de procesamiento para la integración de mensajes de chat de Google puede provocar un ataque DoS de expresión regular en el servidor. • https://gitlab.com/gitlab-org/gitlab/-/issues/434854 https://hackerone.com/reports/2270362 • CWE-400: Uncontrolled Resource Consumption CWE-1333: Inefficient Regular Expression Complexity •
CVE-2024-2454 – Allocation of Resources Without Limits or Throttling in GitLab
https://notcve.org/view.php?id=CVE-2024-2454
The pins endpoint is susceptible to DoS through a crafted request. ... El endpoint de los pines es susceptible a DoS a través de una solicitud manipulada. • https://gitlab.com/gitlab-org/gitlab/-/issues/450405 https://hackerone.com/reports/2408226 • CWE-400: Uncontrolled Resource Consumption CWE-770: Allocation of Resources Without Limits or Throttling •