Bug | stretch | buster | Description |
---|
CVE-2023-3978 | vulnerable | vulnerable (no DSA, postponed) | Text nodes not in the HTML namespace are incorrectly literally rendere ... |
CVE-2022-41717 | vulnerable | vulnerable (no DSA, postponed) | An attacker can cause excessive memory growth in a Go server accepting ... |
CVE-2022-27664 | vulnerable | vulnerable (no DSA, postponed) | In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers ca ... |
CVE-2021-44716 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontro ... |
CVE-2021-33194 | vulnerable (no DSA) | vulnerable (no DSA, postponed) | golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows atta ... |
CVE-2021-31525 | vulnerable (no DSA) | vulnerable (no DSA, postponed) | net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote a ... |
CVE-2019-9514 | fixed | vulnerable (no DSA) | Some HTTP/2 implementations are vulnerable to a reset flood, potential ... |
CVE-2019-9512 | fixed | vulnerable (no DSA, postponed) | Some HTTP/2 implementations are vulnerable to ping floods, potentially ... |