Vulnerabilities > Golang > GO > 0.0.0.20201203163018.be400aefbc4c

DATE CVE VULNERABILITY TITLE RISK
2017-10-05 CVE-2017-1000098 Uncontrolled File Descriptor Consumption vulnerability in Golang GO
The net/http package's Request.ParseMultipartForm method starts writing to temporary files once the request body size surpasses the given "maxMemory" limit.
network
low complexity
golang CWE-769
7.5
2017-10-05 CVE-2017-1000097 Improper Certificate Validation vulnerability in Golang GO
On Darwin, user's trust preferences for root certificates were not honored.
network
low complexity
golang CWE-295
7.5
2017-07-06 CVE-2017-8932 Incorrect Calculation vulnerability in multiple products
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points.
network
high complexity
golang fedoraproject novell opensuse CWE-682
5.9
2016-05-23 CVE-2016-3959 Improper Input Validation vulnerability in multiple products
The Verify function in crypto/dsa/dsa.go in Go before 1.5.4 and 1.6.x before 1.6.1 does not properly check parameters passed to the big integer library, which might allow remote attackers to cause a denial of service (infinite loop) via a crafted public key to a program that uses HTTPS client certificates or SSH server libraries.
network
low complexity
opensuse golang fedoraproject CWE-20
7.5