Search CVE reports
71 – 80 of 94 results
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
10 affected packages
golang-1.10, golang, golang-1.6, golang-1.8, golang-1.9...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | Not in release | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
Acceptance of some invalid Transfer-Encoding headers in the HTTP/1 client in net/http before Go 1.17.12 and Go 1.18.4 allows HTTP request smuggling if combined with an intermediate server that also improperly fails to reject the...
3 affected packages
golang-1.18, golang-1.16, golang-1.13
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang-1.18 | — | Fixed | Fixed | Fixed |
golang-1.16 | — | Not in release | Fixed | Fixed |
golang-1.13 | — | Fixed | Fixed | Fixed |
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.
9 affected packages
golang-1.10, golang, golang-1.6, golang-1.8, golang-1.9...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.15 | — | — | Not in release | Not in release |
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
9 affected packages
golang-1.10, golang, golang-1.6, golang-1.8, golang-1.9...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.15 | — | — | Not in release | Not in release |
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS...
9 affected packages
golang-1.10, golang, golang-1.6, golang-1.8, golang-1.9...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.15 | — | — | Not in release | Not in release |
Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program...
8 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.15...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | — | — | Not in release | Not in release |
golang-1.10 | — | — | Not in release | Not affected |
golang-1.13 | — | — | Not affected | Not affected |
golang-1.14 | — | — | Not affected | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.6 | — | — | Not in release | Not in release |
golang-1.8 | — | — | Not in release | Not affected |
golang-1.9 | — | — | Not in release | Not affected |
In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.
8 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Vulnerable |
golang-1.9 | Not in release | Not in release | Not in release | Vulnerable |
golang-1.10 | Not in release | Not in release | Not in release | Vulnerable |
golang-1.13 | Not in release | Vulnerable | Vulnerable | Vulnerable |
golang-1.14 | Not in release | Not in release | Vulnerable | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of...
9 affected packages
golang-1.10, golang, golang-1.6, golang-1.8, golang-1.9...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.15 | — | — | Not in release | Not in release |
archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename.
8 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.
8 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.15 | — | — | Not in release | Not in release |