Bug | stretch | Description |
---|
CVE-2021-3114 | vulnerable | crypto/elliptic: incorrect operations on the P-224 curve |
CVE-2020-29511 | vulnerable (no DSA, ignored) | The encoding/xml package in Go (all versions) does not correctly prese ... |
CVE-2020-29510 | vulnerable (no DSA, ignored) | The encoding/xml package in Go versions 1.15 and earlier does not corr ... |
CVE-2020-29509 | vulnerable (no DSA, ignored) | The encoding/xml package in Go (all versions) does not correctly prese ... |
CVE-2020-28366 | vulnerable (no DSA, ignored) | Go before 1.14.12 and 1.15.x before 1.15.5 allows Code Injection. ... |
CVE-2020-24553 | vulnerable (no DSA) | Go before 1.14.8 and 1.15.x before 1.15.1 allows XSS because text/html ... |
CVE-2019-9741 | vulnerable (no DSA, ignored) | An issue was discovered in net/http in Go 1.11.5. CRLF injection is po ... |
CVE-2019-9514 | vulnerable (no DSA, ignored) | Some HTTP/2 implementations are vulnerable to a reset flood, potential ... |
CVE-2019-9512 | vulnerable (no DSA, ignored) | Some HTTP/2 implementations are vulnerable to ping floods, potentially ... |
CVE-2019-17596 | vulnerable (no DSA, ignored) | Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to ... |
CVE-2019-16276 | vulnerable (no DSA, ignored) | Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smugglin ... |
CVE-2019-14809 | vulnerable (no DSA, ignored) | net/url in Go before 1.11.13 and 1.12.x before 1.12.8 mishandles malfo ... |
CVE-2017-8932 | vulnerable (no DSA, ignored) | A bug in the standard library ScalarMult implementation of curve P-256 ... |
CVE-2017-15042 | vulnerable (no DSA, ignored) | An unintended cleartext issue exists in Go before 1.8.4 and 1.9.x befo ... |
CVE-2017-15041 | vulnerable (no DSA, ignored) | Go before 1.8.4 and 1.9.x before 1.9.1 allows "go get" remote command ... |
Bug | Description |
---|
CVE-2020-7919 | Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte ... |
CVE-2020-28367 | Go before 1.14.12 and 1.15.x before 1.15.5 allows Argument Injection. ... |
CVE-2020-28362 | Go before 1.14.12 and 1.15.x before 1.15.4 allows Denial of Service. ... |
CVE-2020-16845 | Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loo ... |
CVE-2020-15586 | Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net ... |
CVE-2019-6486 | Go before 1.10.8 and 1.11.x before 1.11.5 mishandles P-521 and P-384 e ... |
CVE-2018-7187 | The "go get" implementation in Go 1.9.4, when the -insecure command-li ... |
CVE-2018-6574 | Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases befor ... |
CVE-2017-1000098 | The net/http package's Request.ParseMultipartForm method starts writin ... |
CVE-2017-1000097 | On Darwin, user's trust preferences for root certificates were not hon ... |