İçeriğe atla
Noroxi

matrixssl kayıtları

matrixssl üreticisine ait 24 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %4,2
Pre-auth RCE
5
Düzeltme kaydı olan
%4,2
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

24 kayıt
  • CVE-2016-6890
    41Planlayın

    Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an

    KritikCVSS 9,8İstismar yokEPSS %6

    matrixssl · matrixssl5 Oca 2017

  • CVE-2019-14431
    40Planlayın

    In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of

    KritikCVSS 9,8İstismar yokEPSS %4

    matrixssl · matrixssl29 Tem 2019

  • CVE-2017-2780
    40Planlayın

    An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.

    KritikCVSS 9,8İstismar yokEPSS %2

    matrixssl · matrixssl22 Haz 2017

  • CVE-2017-2781
    40Planlayın

    An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.

    KritikCVSS 9,8İstismar yokEPSS %2

    matrixssl · matrixssl22 Haz 2017

  • CVE-2022-43974
    40Planlayın

    MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13.

    KritikCVSS 9,8İstismar yokEPSS %2

    matrixssl · matrixssl9 Oca 2023

  • CVE-2019-13470
    39İzleyin

    MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.

    KritikCVSS 9,8İstismar yokEPSS %2

    matrixssl · matrixssl9 Tem 2019

  • CVE-2019-10914
    39İzleyin

    pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509

    KritikCVSS 9,8İstismar yokEPSS %1

    matrixssl · matrixssl8 Nis 2019

  • CVE-2017-2782
    36İzleyin

    An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.

    KritikCVSS 9,1İstismar yokEPSS %1

    matrixssl · matrixssl22 Haz 2017

  • CVE-2016-6892
    31İzleyin

    The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory)

    YüksekCVSS 7,5İstismar yokEPSS %2

    matrixssl · matrixssl5 Oca 2017

  • CVE-2016-6891
    31İzleyin

    MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in

    YüksekCVSS 7,5İstismar yokEPSS %2

    matrixssl · matrixssl5 Oca 2017

  • CVE-2019-16747
    31İzleyin

    In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via

    YüksekCVSS 7,5İstismar yokEPSS %2

    matrixssl · matrixssl30 Ara 2020

  • CVE-2016-6886
    31İzleyin

    The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via

    YüksekCVSS 7,5İstismar yokEPSS %2

    matrixssl · matrixssl13 Oca 2017

  • CVE-2016-6885
    30İzleyin

    The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base

    YüksekCVSS 7,5İstismar yokEPSS %1

    matrixssl · matrixssl13 Oca 2017

  • CVE-2022-46505
    30İzleyin

    An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero

    YüksekCVSS 7,5Kavram kanıtıEPSS %1

    matrixssl · matrixssl18 Oca 2023

  • CVE-2023-24609
    30İzleyin

    Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension par

    YüksekCVSS 7,5İstismar yokEPSS %1

    rambus · tls toolkit22 Ara 2023

  • CVE-2016-6883
    27İzleyin

    MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher varian

    OrtaCVSS 5,9SilahlaştırılmışEPSS %14

    matrixssl · matrixssl3 Mar 2017

  • CVE-2016-6884
    26İzleyin

    TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bou

    OrtaCVSS 6,5İstismar yokEPSS %1

    matrixssl · matrixssl3 Mar 2017

  • CVE-2016-8671
    23İzleyin

    The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attacker

    OrtaCVSS 5,9İstismar yokEPSS %1

    matrixssl · matrixssl13 Oca 2017

  • CVE-2016-6882
    23İzleyin

    MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key inf

    OrtaCVSS 5,9İstismar yokEPSS %1

    matrixssl · matrixssl3 Mar 2017

  • CVE-2019-13629
    23İzleyin

    MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.

    OrtaCVSS 5,9İstismar yokEPSS %1

    matrixssl · matrixssl3 Eki 2019

  • CVE-2016-6887
    23İzleyin

    The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attacker

    OrtaCVSS 5,9İstismar yokEPSS %1

    matrixssl · matrixssl13 Oca 2017

  • MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certifi

    OrtaCVSS 5,9İstismar yokEPSS %0

    matrixssl · matrixssl9 Oca 2018

  • MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g.

    OrtaCVSS 5,3İstismar yokEPSS %1

    matrixssl · matrixssl22 Oca 2018

  • CVE-2018-12439
    18İzleyin

    MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or R

    OrtaCVSS 4,7İstismar yokEPSS %0

    matrixssl · matrixssl14 Haz 2018