İçeriğe atla
Noroxi

wolfSSL kayıtları

wolfssl üreticisine ait 153 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
2 · %1,3
Pre-auth RCE
3
Düzeltme kaydı olan
%69,3
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

153 kayıt
  • CVE-2009-4484
    51Planlayın

    Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysq

    YüksekCVSS 7,5SilahlaştırılmışEPSS %70

    oracle · mysql30 Ara 2009

  • CVE-2019-11873
    42Planlayın

    wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size.

    KritikCVSS 9,8İstismar yokEPSS %9

    wolfssl · wolfssl23 May 2019

  • CVE-2017-2800
    42Planlayın

    A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certif

    KritikCVSS 9,8Kavram kanıtıEPSS %9

    wolfssl · wolfssl24 May 2017

  • CVE-2020-36177
    40Planlayın

    RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest s

    KritikCVSS 9,8İstismar yokEPSS %4

    wolfssl · wolfssl6 Oca 2021

  • CVE-2014-2896
    40Planlayın

    The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified

    KritikCVSS 9,8İstismar yokEPSS %3

    wolfssl · wolfssl28 Oca 2020

  • CVE-2014-2897
    40Planlayın

    The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows re

    KritikCVSS 9,8İstismar yokEPSS %3

    wolfssl · wolfssl28 Oca 2020

  • CVE-2014-2898
    40Planlayın

    wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers

    KritikCVSS 9,8İstismar yokEPSS %3

    wolfssl · wolfssl28 Oca 2020

  • CVE-2019-6439
    40Planlayın

    examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.

    KritikCVSS 9,8İstismar yokEPSS %3

    wolfssl · wolfssl15 Oca 2019

  • CVE-2024-5991
    40Planlayın

    Buffer overread in domain name matching

    KritikCVSS 10,0İstismar yokEPSS %1

    wolfssl · wolfssl27 Ağu 2024

  • CVE-2021-37155
    39İzleyin

    wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the seria

    KritikCVSS 9,8İstismar yokEPSS %1

    wolfssl · wolfssl21 Tem 2021

  • CVE-2019-16748
    39İzleyin

    In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking.

    KritikCVSS 9,8İstismar yokEPSS %1

    wolfssl · wolfssl24 Eyl 2019

  • CVE-2019-15651
    39İzleyin

    wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte

    KritikCVSS 9,8İstismar yokEPSS %1

    wolfssl · wolfssl26 Ağu 2019

  • CVE-2022-42905
    37İzleyin

    In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network atta

    KritikCVSS 9,1İstismar yokEPSS %2

    wolfssl · wolfssl6 Kas 2022

  • CVE-2026-5194
    37İzleyin

    wolfSSL ECDSA Certificate Verification

    KritikCVSS 9,3İstismar yokEPSS %0

    wolfssl · wolfssl9 Nis 2026

  • CVE-2022-23408
    36İzleyin

    wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations.

    KritikCVSS 9,1İstismar yokEPSS %1

    wolfssl · wolfssl18 Oca 2022

  • CVE-2024-0901
    36İzleyin

    SEGV and out of bounds memory read from malicious packet

    KritikCVSS 9,1İstismar yokEPSS %1

    wolfssl · wolfssl25 Mar 2024

  • CVE-2023-6936
    36İzleyin

    Heap-buffer over-read with WOLFSSL_CALLBACKS

    KritikCVSS 9,1İstismar yokEPSS %1

    wolfssl · wolfssl20 Şub 2024

  • CVE-2023-3724
    35İzleyin

    TLS 1.3 client issue handling malicious server when not including a KSE and PSK extension

    YüksekCVSS 8,8İstismar yokEPSS %1

    wolfssl · wolfssl17 Tem 2023

  • CVE-2024-1545
    35İzleyin

    Fault Injection of RSA encryption in WolfCrypt

    YüksekCVSS 8,8İstismar yokEPSS %1

    wolfssl · wolfssl29 Ağu 2024

  • CVE-2026-6679
    35İzleyin

    DTLS 1.3 ACK serialization heap buffer overflow via integer truncation

    YüksekCVSS 8,8İstismar yokEPSS %1

    wolfssl · wolfssl25 Haz 2026

  • CVE-2024-2881
    35İzleyin

    Fault Injection of EdDSA signature in WolfCrypt

    YüksekCVSS 8,8İstismar yokEPSS %0

    wolfssl · wolfssl29 Ağu 2024

  • CVE-2026-5500
    34İzleyin

    Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass

    YüksekCVSS 8,7İstismar yokEPSS %0

    wolfssl · wolfssl10 Nis 2026

  • CVE-2026-11310
    34İzleyin

    X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring

    YüksekCVSS 8,7İstismar yokEPSS %0

    wolfssl · wolfssl25 Haz 2026

  • CVE-2026-5501
    34İzleyin

    Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates

    YüksekCVSS 8,6İstismar yokEPSS %0

    wolfssl · wolfssl10 Nis 2026

  • CVE-2026-5264
    33İzleyin

    DTLS 1.3 ACK heap buffer overflow

    YüksekCVSS 8,3İstismar yokEPSS %1

    wolfssl · wolfssl9 Nis 2026