Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.
A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.
Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.
| Product | Status | Versions | Remediation | Source | |
|---|---|---|---|---|---|
| golang | affected | >= 1.12.0, < 1.12.16 | vendor fix → 1.12.16 | osv BIT-golang-2020-0601 | |
| golang | affected | >= 1.13.0, < 1.13.7 | vendor fix → 1.13.7 | osv BIT-golang-2020-0601 | |
| https://github.com/golang/go | affected | >= 05e77d41914d247a1e7caf37d7125ccaa5a53505, < deac3221fc4cd365fb40d269dd56551e9d354356 | vendor fix → deac3221fc4cd365fb40d269dd56551e9d354356 | osv | |
| https://github.com/golang/go | affected | >= cc8838d645b2b7026c1f3aaceb011775c5ca3a08, < 7d2473dc81c659fba3f3b83bc6e93ca5fe37a898 | vendor fix → 7d2473dc81c659fba3f3b83bc6e93ca5fe37a898 | osv | |
| stdlib | affected | < 1.12.16 | vendor fix → 1.12.16 | osv GO-2022-0535 | |
| stdlib | affected | >= 1.13.0-0, < 1.13.7 | vendor fix → 1.13.7 | osv GO-2022-0535 | |
| golang | fixed | 1.12.16 | vendor fix → 1.12.16 | osv BIT-golang-2020-0601 | |
| golang | fixed | 1.13.7 | vendor fix → 1.13.7 | osv BIT-golang-2020-0601 | |
| https://github.com/golang/go | fixed | deac3221fc4cd365fb40d269dd56551e9d354356 | vendor fix → deac3221fc4cd365fb40d269dd56551e9d354356 | osv | |
| https://github.com/golang/go | fixed | 7d2473dc81c659fba3f3b83bc6e93ca5fe37a898 | vendor fix → 7d2473dc81c659fba3f3b83bc6e93ca5fe37a898 | osv | |
| stdlib | fixed | 1.12.16 | vendor fix → 1.12.16 | osv GO-2022-0535 | |
| stdlib | fixed | 1.13.7 | vendor fix → 1.13.7 | osv GO-2022-0535 | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1803 for 32-bit Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1803 for x64-based Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1803 for ARM64-based Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1809 for 32-bit Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1809 for x64-based Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1809 for ARM64-based Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1709 for 32-bit Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1709 for x64-based Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1709 for ARM64-based Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 for 32-bit Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 for x64-based Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1607 for 32-bit Systems | none available | cve_cna | |
| Microsoft/Windows Microsoft · Windows | affected | 10 Version 1607 for x64-based Systems | none available | cve_cna | |
| Microsoft/Windows 10 Version 1903 for 32-bit Systems Microsoft · Windows 10 Version 1903 for 32-bit Systems | affected | no version stated vendor label: all versions | none available | cve_cna | |
| Microsoft/Windows 10 Version 1903 for ARM64-based Systems Microsoft · Windows 10 Version 1903 for ARM64-based Systems | affected | no version stated vendor label: all versions | none available | cve_cna | |
| Microsoft/Windows 10 Version 1903 for x64-based Systems Microsoft · Windows 10 Version 1903 for x64-based Systems | affected | no version stated vendor label: all versions | none available | cve_cna | |
| Microsoft/Windows 10 Version 1909 for 32-bit Systems Microsoft · Windows 10 Version 1909 for 32-bit Systems | affected | no version stated vendor label: all versions | none available | cve_cna | |
| Microsoft/Windows 10 Version 1909 for ARM64-based Systems Microsoft · Windows 10 Version 1909 for ARM64-based Systems | affected | no version stated vendor label: all versions | none available | cve_cna | |
| Microsoft/Windows 10 Version 1909 for x64-based Systems Microsoft · Windows 10 Version 1909 for x64-based Systems | affected | no version stated vendor label: all versions | none available | cve_cna | |
| Microsoft/Windows Server Microsoft · Windows Server | affected | version 1803 (Core Installation) | none available | cve_cna | |
| Microsoft/Windows Server Microsoft · Windows Server | affected | 2019 | none available | cve_cna | |
| Microsoft/Windows Server Microsoft · Windows Server | affected | 2019 (Core installation) | none available | cve_cna | |
| Microsoft/Windows Server Microsoft · Windows Server | affected | 2016 | none available | cve_cna | |
| Microsoft/Windows Server Microsoft · Windows Server | affected | 2016 (Core installation) | none available | cve_cna | |
| Microsoft/Windows Server, version 1903 (Server Core installation) Microsoft · Windows Server, version 1903 (Server Core installation) | affected | no version stated vendor label: all versions | none available | cve_cna | |
| Microsoft/Windows Server, version 1909 (Server Core installation) Microsoft · Windows Server, version 1909 (Server Core installation) | affected | no version stated vendor label: all versions | none available | cve_cna |
A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.