Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 22

Количество 22

fstec логотип

BDU:2026-03601

6 месяцев назад

Уязвимость языка программирования Golang, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код

CVSS3: 7
EPSS: Низкий
redos логотип

ROS-20260209-73-0047

6 месяцев назад

Уязвимость golang

CVSS3: 7
EPSS: Низкий
ubuntu логотип

CVE-2025-68119

6 месяцев назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
EPSS: Низкий
redhat логотип

CVE-2025-68119

6 месяцев назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 6.7
EPSS: Низкий
nvd логотип

CVE-2025-68119

6 месяцев назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2025-68119

6 месяцев назад

Downloading and building modules with malicious version strings can ca ...

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-cm6p-qc7v-m3jw

6 месяцев назад

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20220-1

6 месяцев назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0789-1

5 месяцев назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0687-1

5 месяцев назад

Security update for go1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0426-1

6 месяцев назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20085-1

7 месяцев назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20077-1

7 месяцев назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0219-1

7 месяцев назад

Security update for go1.24

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0218-1

7 месяцев назад

Security update for go1.25

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20619-1

3 месяца назад

Security update for coredns

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20301-1

5 месяцев назад

Security update for go1.25-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0308-1

6 месяцев назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0296-1

6 месяцев назад

Security update for go1.24-openssl

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20308-1

5 месяцев назад

Security update for go1.24-openssl

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-03601

Уязвимость языка программирования Golang, связанная с записью за границами буфера в памяти, позволяющая нарушителю выполнить произвольный код

CVSS3: 7
0%
Низкий
6 месяцев назад
redos логотип
ROS-20260209-73-0047

Уязвимость golang

CVSS3: 7
0%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 6.7
0%
Низкий
6 месяцев назад
nvd логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
0%
Низкий
6 месяцев назад
debian логотип
CVE-2025-68119

Downloading and building modules with malicious version strings can ca ...

CVSS3: 7
0%
Низкий
6 месяцев назад
github логотип
GHSA-cm6p-qc7v-m3jw

Downloading and building modules with malicious version strings can cause local code execution. On systems with Mercurial (hg) installed, downloading modules from non-standard sources (e.g., custom domains) can cause unexpected code execution due to how external VCS commands are constructed. This issue can also be triggered by providing a malicious version string to the toolchain. On systems with Git installed, downloading and building modules with malicious version strings can allow an attacker to write to arbitrary files on the filesystem. This can only be triggered by explicitly providing the malicious version strings to the toolchain and does not affect usage of @latest or bare module paths.

CVSS3: 7
0%
Низкий
6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20220-1

Security update for go1.24

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0789-1

Security update for go1.24-openssl

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0687-1

Security update for go1

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0426-1

Security update for go1.24

6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20085-1

Security update for go1.25

7 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20077-1

Security update for go1.24

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0219-1

Security update for go1.24

7 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0218-1

Security update for go1.25

7 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20619-1

Security update for coredns

3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20301-1

Security update for go1.25-openssl

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0308-1

Security update for go1.24-openssl

6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0296-1

Security update for go1.24-openssl

6 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20308-1

Security update for go1.24-openssl

5 месяцев назад

Уязвимостей на страницу