Vulnerabilities
Vulnerable Software
Golang:  >> Net  >> 2018-09-21  Security Vulnerabilities
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <table><math><select><mi><select></table>, leading to an infinite loop during an html.Parse call because inSelectIM and inSelectInTableIM do not comply with a specification.
CVSS Score
7.5
EPSS Score
0.007
Published
2018-10-01
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.
CVSS Score
7.5
EPSS Score
0.009
Published
2018-10-01
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.
CVSS Score
7.5
EPSS Score
0.01
Published
2018-10-01


Contact Us

Shodan ® - All rights reserved