Search CVE reports
71 – 80 of 94 results
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.
10 affected packages
golang-1.13, golang, golang-1.10, golang-1.14, golang-1.15...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
10 affected packages
golang, golang-1.6, golang-1.8, golang-1.9, golang-1.10...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.17 | Not in release | Needs evaluation | Not in release | Not in release |
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.
9 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.15...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
9 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.15...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of...
9 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.15...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS...
9 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.15...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.16 | Not in release | Not in release | Needs evaluation | Needs evaluation |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.
9 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.15...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | — | Not in release | Not in release | Not in release |
golang-1.10 | — | Not in release | Not in release | Not affected |
golang-1.13 | — | Not affected | Not affected | Not affected |
golang-1.14 | — | Not in release | Not affected | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.16 | — | Not in release | Not affected | Not affected |
golang-1.6 | — | Not in release | Not in release | Not in release |
golang-1.8 | — | Not in release | Not in release | Not affected |
golang-1.9 | — | Not in release | Not in release | Not affected |
archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename.
8 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.15...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
encoding/xml in Go before 1.15.9 and 1.16.x before 1.16.1 has an infinite loop if a custom TokenReader (for xml.NewTokenDecoder) returns EOF in the middle of an element. This can occur in the Decode, DecodeElement, or Skip method.
8 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.15...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | Not in release | Not in release | Not in release | Not in release |
golang-1.10 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.13 | Not in release | Needs evaluation | Needs evaluation | Needs evaluation |
golang-1.14 | Not in release | Not in release | Needs evaluation | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.6 | Not in release | Not in release | Not in release | Not in release |
golang-1.8 | Not in release | Not in release | Not in release | Needs evaluation |
golang-1.9 | Not in release | Not in release | Not in release | Needs evaluation |
Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program...
8 affected packages
golang, golang-1.10, golang-1.13, golang-1.14, golang-1.15...
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
golang | — | — | Not in release | Not in release |
golang-1.10 | — | — | Not in release | Not affected |
golang-1.13 | — | — | Not affected | Not affected |
golang-1.14 | — | — | Not affected | Not in release |
golang-1.15 | — | — | Not in release | Not in release |
golang-1.6 | — | — | Not in release | Not in release |
golang-1.8 | — | — | Not in release | Not affected |
golang-1.9 | — | — | Not in release | Not affected |