CVE-2023-48795
- EPSS 93.31%
- Veröffentlicht 18.12.2023 16:15:10
- Zuletzt bearbeitet 12.05.2026 11:16:15
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client a...
CVE-2019-11841
- EPSS 2%
- Veröffentlicht 22.05.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:52
A message-forgery issue was discovered in crypto/openpgp/clearsign/clearsign.go in supplementary Go cryptography libraries 2019-03-25. According to the OpenPGP Message Format specification in RFC 4880 chapter 7, a cleartext signed message can contain...
CVE-2019-11840
- EPSS 3.47%
- Veröffentlicht 09.05.2019 16:29:00
- Zuletzt bearbeitet 18.05.2026 12:04:40
An issue was discovered in the supplementary Go cryptography library, golang.org/x/crypto, before v0.0.0-20190320223903-b7391e95e576. A flaw was found in the amd64 implementation of the golang.org/x/crypto/salsa20 and golang.org/x/crypto/salsa20/sals...
CVE-2017-3204
- EPSS 3.16%
- Veröffentlicht 04.04.2017 14:59:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The Go SSH library (x/crypto/ssh) by default does not verify host keys, facilitating man-in-the-middle attacks. Default behavior changed in commit e4e2799 to require explicitly registering a hostkey verification mechanism.