CVE-2021-39293
- EPSS 0.04%
- Veröffentlicht 24.01.2022 01:15:07
- Zuletzt bearbeitet 21.11.2024 06:19:08
In archive/zip in Go before 1.16.8 and 1.17.x before 1.17.1, a crafted archive header (falsely designating that many files are present) can cause a NewReader or OpenReader panic. NOTE: this issue exists because of an incomplete fix for CVE-2021-33196...
CVE-2021-44716
- EPSS 0.1%
- Veröffentlicht 01.01.2022 05:15:08
- Zuletzt bearbeitet 21.11.2024 06:31:26
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
CVE-2021-44717
- EPSS 0.44%
- Veröffentlicht 01.01.2022 05:15:08
- Zuletzt bearbeitet 21.11.2024 06:31:27
Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file or unintended network connection as a consequence of erroneous closing of file descriptor 0 after file-descriptor exhaustion.
CVE-2021-41771
- EPSS 0.84%
- Veröffentlicht 08.11.2021 06:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:44
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
CVE-2021-41772
- EPSS 0.06%
- Veröffentlicht 08.11.2021 06:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:44
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.
CVE-2021-38297
- EPSS 10.63%
- Veröffentlicht 18.10.2021 06:15:06
- Zuletzt bearbeitet 21.11.2024 06:16:44
Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.
CVE-2021-36221
- EPSS 0.23%
- Veröffentlicht 08.08.2021 06:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:20
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
CVE-2021-29923
- EPSS 0.12%
- Veröffentlicht 07.08.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 06:01:59
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretati...
CVE-2021-33195
- EPSS 0.03%
- Veröffentlicht 02.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:29
Go before 1.15.13 and 1.16.x before 1.16.5 has functions for DNS lookups that do not validate replies from DNS servers, and thus a return value may contain an unsafe injection (e.g., XSS) that does not conform to the RFC1035 format.
CVE-2021-33196
- EPSS 0.06%
- Veröffentlicht 02.08.2021 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:08:29
In archive/zip in Go before 1.15.13 and 1.16.x before 1.16.5, a crafted file count (in an archive's header) can cause a NewReader or OpenReader panic.