Skip to main content

Vendor archive

dfinity CVEs

Beta · best-effort

5 CVEs tagged to vendor dfinity1 Critical, 2 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-11991

Published Dec 9, 2024

Motoko's incremental garbage collector is impacted by an uninitialized memory access bug, caused by incorrect use of write barriers in a few locations. This vulnerability could po…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4435

Published May 21, 2024

When storing unbounded types in a BTreeMap, a node is represented as a linked list of "memory chunks". It was discovered recently that when we deallocate a node, in some cases onl…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1631

Published Feb 21, 2024

Impact: The library offers a function to generate an ed25519 key pair via Ed25519KeyIdentity.generate with an optional param to provide a 32 byte seed value, which will then be us…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-6245

Published Dec 8, 2023

The Candid library causes a Denial of Service while parsing a specially crafted payload with 'empty' data type. For example, if the payload is `record { * ; empty }` and the can…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1