Search CVE reports


Toggle filters

71 – 72 of 72 results


CVE-2020-14039

Medium priority
Ignored

In Go before 1.13.13 and 1.14.x before 1.14.5, Certificate.Verify may lack a check on the VerifyOptions.KeyUsages EKU requirements (if VerifyOptions.Roots equals nil and the installation is on Windows). Thus, X.509 certificate...

10 affected packages

golang, golang-1.10, golang-1.11, golang-1.12, golang-1.13...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
golang Not in release Not in release Not in release
golang-1.10 Not in release Not affected Not affected
golang-1.11 Not in release Not in release Not in release
golang-1.12 Not in release Not in release Not in release
golang-1.13 Not affected Not affected Not affected
golang-1.14 Not affected Not in release Not in release
golang-1.15 Not in release Not in release Not in release
golang-1.6 Not in release Not in release Not affected
golang-1.8 Not in release Not affected Not in release
golang-1.9 Not in release Not affected Not in release
Show all 10 packages Show less packages

CVE-2020-7919

Medium priority

Some fixes available 3 of 12

Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.

9 affected packages

golang, golang-1.10, golang-1.11, golang-1.12, golang-1.13...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
golang Not in release Not in release Not in release Not in release Not in release
golang-1.10 Not in release Not in release Not in release Vulnerable Needs evaluation
golang-1.11 Not in release Not in release Not in release Not in release Not in release
golang-1.12 Not in release Not in release Not in release Not in release Not in release
golang-1.13 Not in release Not affected Not affected Vulnerable Vulnerable
golang-1.14 Not in release Not in release Fixed Not in release Not in release
golang-1.6 Not in release Not in release Not in release Not in release Not affected
golang-1.8 Not in release Not in release Not in release Not affected Not in release
golang-1.9 Not in release Not in release Not in release Not affected Not in release
Show all 9 packages Show less packages