Vulnerabilities
Vulnerable Software
Golang:  >> Go  >> 1.17.1  Security Vulnerabilities
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
CVSS Score
9.1
EPSS Score
0.0
Published
2022-02-11
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
CVSS Score
7.5
EPSS Score
0.001
Published
2022-01-01
Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustion.
CVSS Score
4.8
EPSS Score
0.002
Published
2022-01-01
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
CVSS Score
7.5
EPSS Score
0.009
Published
2021-11-08
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.
CVSS Score
7.5
EPSS Score
0.001
Published
2021-11-08
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.
CVSS Score
9.8
EPSS Score
0.106
Published
2021-10-18


Contact Us

Shodan ® - All rights reserved