Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2022-23806
Disclosure Date: February 11, 2022 (last updated November 29, 2024)
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
1
Attacker Value
Unknown
CVE-2022-29526
Disclosure Date: June 23, 2022 (last updated October 07, 2023)
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
0
Attacker Value
Unknown
CVE-2022-23773
Disclosure Date: February 11, 2022 (last updated November 29, 2024)
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.
0
Attacker Value
Unknown
CVE-2022-23772
Disclosure Date: February 11, 2022 (last updated November 29, 2024)
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.
0