Vulnerabilities > Goxmldsig Project

DATE CVE VULNERABILITY TITLE RISK
2020-09-29 CVE-2020-15216 Improper Verification of Cryptographic Signature vulnerability in multiple products
In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one.
network
low complexity
goxmldsig-project fedoraproject CWE-347
6.5
2020-08-23 CVE-2020-7711 NULL Pointer Dereference vulnerability in Goxmldsig Project Goxmldsig
This affects all versions of package github.com/russellhaering/goxmldsig.
network
low complexity
goxmldsig-project CWE-476
5.0