Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2022-23806

Disclosure Date: February 11, 2022 (last updated November 29, 2024)
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
Attacker Value
Unknown

CVE-2022-24675

Disclosure Date: April 20, 2022 (last updated October 07, 2023)
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
Attacker Value
Unknown

CVE-2022-23773

Disclosure Date: February 11, 2022 (last updated November 29, 2024)
cmd/go in Go before 1.16.14 and 1.17.x before 1.17.7 can misinterpret branch names that falsely appear to be version tags. This can lead to incorrect access control if an actor is supposed to be able to create branches but not tags.
Attacker Value
Unknown

CVE-2022-23772

Disclosure Date: February 11, 2022 (last updated November 29, 2024)
Rat.SetString in math/big in Go before 1.16.14 and 1.17.x before 1.17.7 has an overflow that can lead to Uncontrolled Memory Consumption.