Known vulnerabilities in go1.23-openssl-debuginfo
Vendor:
SUSE
Software:
go1.23-openssl-debuginfo
Software CPE:
cpe:2.3:o:suse:go1.23-openssl-debuginfo:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
13
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (13)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU114341 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2025-4674 |
CWE-78 | High | 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1 | 21.08.2025 |
SB2025082138 SB2025082164 SB2025082165 and 19 more |
||
| #VU114080 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') CVE-2025-47907 |
CWE-362 | Low | 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1 | 14.08.2025 |
SB2025081423 SB2025081424 SB2025081425 and 50 more |
||
| #VU114079 - Improper input validation CVE-2025-47906 |
CWE-20 | Low | 1.23.12-150000.1.18.1, 1.23.12-150600.13.9.1 | 14.08.2025 |
SB2025081423 SB2025081424 SB2025081425 and 130 more |
||
| #VU110252 - Improper Link Resolution Before File Access ('Link Following') CVE-2025-0913 |
CWE-59 | Low | 1.23.12-150600.13.9.1 | 07.06.2025 |
SB2025060702 SB2025061002 SB2025061003 and 8 more |
||
| #VU110251 - Exposure of sensitive information to an unauthorized actor CVE-2025-4673 |
CWE-200 | Low | 1.23.12-150600.13.9.1 | 07.06.2025 |
SB2025060701 SB2025060702 SB2025061002 and 35 more |
||
| #VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2025-22871 |
CWE-444 | Medium | 1.23.9-150000.1.9.1, 1.23.12-150600.13.9.1 | 05.04.2025 |
SB2025040507 SB2025040508 SB2025040739 and 109 more |
||
| #VU106253 - Improper input validation CVE-2025-22870 |
CWE-20 | Medium | 1.23.9-150000.1.9.1, 1.23.12-150600.13.9.1 | 30.03.2025 |
SB2025033001 SB2025033002 SB2025033003 and 106 more |
||
| #VU103932 - Missing release of memory after effective lifetime CVE-2025-22866 |
CWE-401 | Low | 1.23.9-150000.1.9.1, 1.23.12-150600.13.9.1 | 12.02.2025 |
SB20250212100 SB20250212101 SB20250212102 and 27 more |
||
| #VU103457 - Improper input validation CVE-2024-45341 |
CWE-20 | Low | 1.23.9-150000.1.9.1, 1.23.12-150600.13.9.1 | 30.01.2025 |
SB2025013039 SB2025013043 SB2025013044 and 23 more |
||
| #VU103455 - Exposure of sensitive information to an unauthorized actor CVE-2024-45336 |
CWE-200 | Low | 1.23.9-150000.1.9.1, 1.23.12-150600.13.9.1 | 30.01.2025 |
SB2025013039 SB2025013043 SB2025013044 and 38 more |
||
| #VU97217 - Resource exhaustion CVE-2024-34158 |
CWE-400 | Medium | 1.23.2.2-150000.1.3.1, 1.23.2.2-150600.13.3.1 | 12.09.2024 |
SB2024091261 SB2024091264 SB2024091265 and 76 more |
||
| #VU97216 - Resource exhaustion CVE-2024-34156 |
CWE-400 | Medium | 1.23.2.2-150000.1.3.1, 1.23.2.2-150600.13.3.1 | 12.09.2024 |
SB2024091261 SB2024091264 SB2024091265 and 143 more |
||
| #VU97215 - Resource exhaustion CVE-2024-34155 |
CWE-400 | Medium | 1.23.2.2-150000.1.3.1, 1.23.2.2-150600.13.3.1 | 12.09.2024 |
SB2024091261 SB2024091264 SB2024091265 and 81 more |