VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Golang
>
GO
> 1.11.0
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2018-12-14
CVE-2018-16874
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters).
network
high complexity
golang
opensuse
suse
debian
8.1
8.1
2018-12-14
CVE-2018-16873
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly.
network
high complexity
golang
opensuse
suse
debian
8.1
8.1
«
Previous
1
2
...
6
7
8
9
10
(current)
»