wolfSSL kayıtları
wolfssl üreticisine ait 153 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %1,3
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %69,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-295 Improper Certificate Validation20
- CWE-787 Out-of-bounds Write16
- CWE-125 Out-of-bounds Read14
- CWE-203 Observable Discrepancy11
- CWE-122 Heap-based Buffer Overflow9
- CWE-20 Improper Input Validation8
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
153 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
51Planlayın | CVE-2009-4484Silahlaştırılmış | Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqoracle · mysql · CWE-787 | Yüksek7,5 | — | %69,6 | 30 Ara 2009 |
42Planlayın | CVE-2019-11873İstismar yok | wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size.wolfssl · wolfssl · CWE-787 | Kritik9,8 | — | %8,8 | 23 May 2019 |
42Planlayın | CVE-2017-2800Kavram kanıtı | A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certifwolfssl · wolfssl · CWE-295 | Kritik9,8 | — | %8,5 | 24 May 2017 |
40Planlayın | CVE-2020-36177İstismar yok | RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest swolfssl · wolfssl · CWE-787 | Kritik9,8 | — | %3,5 | 6 Oca 2021 |
40Planlayın | CVE-2014-2896İstismar yok | The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified wolfssl · wolfssl · CWE-125 | Kritik9,8 | — | %2,8 | 28 Oca 2020 |
40Planlayın | CVE-2014-2897İstismar yok | The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows rewolfssl · wolfssl · CWE-125 | Kritik9,8 | — | %2,8 | 28 Oca 2020 |
40Planlayın | CVE-2014-2898İstismar yok | wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggerswolfssl · wolfssl · CWE-125 | Kritik9,8 | — | %2,8 | 28 Oca 2020 |
40Planlayın | CVE-2019-6439İstismar yok | examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.wolfssl · wolfssl · CWE-787 | Kritik9,8 | — | %2,6 | 15 Oca 2019 |
40Planlayın | CVE-2024-5991İstismar yok | Buffer overread in domain name matchingwolfssl · wolfssl · CWE-125 | Kritik10,0 | — | %0,6 | 27 Ağu 2024 |
39İzleyin | CVE-2021-37155İstismar yok | wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the seriawolfssl · wolfssl | Kritik9,8 | — | %1,5 | 21 Tem 2021 |
39İzleyin | CVE-2019-16748İstismar yok | In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking.wolfssl · wolfssl · CWE-125 | Kritik9,8 | — | %1,2 | 24 Eyl 2019 |
39İzleyin | CVE-2019-15651İstismar yok | wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN bytewolfssl · wolfssl · CWE-125 | Kritik9,8 | — | %1,0 | 26 Ağu 2019 |
37İzleyin | CVE-2022-42905İstismar yok | In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attawolfssl · wolfssl · CWE-125 | Kritik9,1 | — | %2,1 | 6 Kas 2022 |
37İzleyin | CVE-2026-5194İstismar yok | wolfSSL ECDSA Certificate Verificationwolfssl · wolfssl · CWE-295 | Kritik9,3 | — | %0,3 | 9 Nis 2026 |
36İzleyin | CVE-2022-23408İstismar yok | wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations.wolfssl · wolfssl · CWE-330 | Kritik9,1 | — | %1,4 | 18 Oca 2022 |
36İzleyin | CVE-2024-0901İstismar yok | SEGV and out of bounds memory read from malicious packetwolfssl · wolfssl · CWE-129 | Kritik9,1 | — | %0,7 | 25 Mar 2024 |
36İzleyin | CVE-2023-6936İstismar yok | Heap-buffer over-read with WOLFSSL_CALLBACKSwolfssl · wolfssl · CWE-125 | Kritik9,1 | — | %0,6 | 20 Şub 2024 |
35İzleyin | CVE-2023-3724İstismar yok | TLS 1.3 client issue handling malicious server when not including a KSE and PSK extensionwolfssl · wolfssl · CWE-20 | Yüksek8,8 | — | %0,7 | 17 Tem 2023 |
35İzleyin | CVE-2024-1545İstismar yok | Fault Injection of RSA encryption in WolfCryptwolfssl · wolfssl · CWE-252 | Yüksek8,8 | — | %0,6 | 29 Ağu 2024 |
35İzleyin | CVE-2026-6679İstismar yok | DTLS 1.3 ACK serialization heap buffer overflow via integer truncationwolfssl · wolfssl · CWE-190 | Yüksek8,8 | — | %0,5 | 25 Haz 2026 |
35İzleyin | CVE-2024-2881İstismar yok | Fault Injection of EdDSA signature in WolfCryptwolfssl · wolfssl · CWE-252 | Yüksek8,8 | — | %0,5 | 29 Ağu 2024 |
34İzleyin | CVE-2026-5500İstismar yok | Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypasswolfssl · wolfssl · CWE-20 | Yüksek8,7 | — | %0,4 | 10 Nis 2026 |
34İzleyin | CVE-2026-11310İstismar yok | X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoringwolfssl · wolfssl · CWE-295 | Yüksek8,7 | — | %0,2 | 25 Haz 2026 |
34İzleyin | CVE-2026-5501İstismar yok | Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificateswolfssl · wolfssl · CWE-295 | Yüksek8,6 | — | %0,2 | 10 Nis 2026 |
33İzleyin | CVE-2026-5264İstismar yok | DTLS 1.3 ACK heap buffer overflowwolfssl · wolfssl · CWE-122 | Yüksek8,3 | — | %0,6 | 9 Nis 2026 |
- CVE-2009-448451Planlayın
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysq
YüksekCVSS 7,5SilahlaştırılmışEPSS %70oracle · mysql30 Ara 2009
- CVE-2019-1187342Planlayın
wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size.
KritikCVSS 9,8İstismar yokEPSS %9wolfssl · wolfssl23 May 2019
- CVE-2017-280042Planlayın
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certif
KritikCVSS 9,8Kavram kanıtıEPSS %9wolfssl · wolfssl24 May 2017
- CVE-2020-3617740Planlayın
RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest s
KritikCVSS 9,8İstismar yokEPSS %4wolfssl · wolfssl6 Oca 2021
- CVE-2014-289640Planlayın
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified
KritikCVSS 9,8İstismar yokEPSS %3wolfssl · wolfssl28 Oca 2020
- CVE-2014-289740Planlayın
The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows re
KritikCVSS 9,8İstismar yokEPSS %3wolfssl · wolfssl28 Oca 2020
- CVE-2014-289840Planlayın
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers
KritikCVSS 9,8İstismar yokEPSS %3wolfssl · wolfssl28 Oca 2020
- CVE-2019-643940Planlayın
examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.
KritikCVSS 9,8İstismar yokEPSS %3wolfssl · wolfssl15 Oca 2019
- CVE-2024-599140Planlayın
Buffer overread in domain name matching
KritikCVSS 10,0İstismar yokEPSS %1wolfssl · wolfssl27 Ağu 2024
- CVE-2021-3715539İzleyin
wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the seria
KritikCVSS 9,8İstismar yokEPSS %1wolfssl · wolfssl21 Tem 2021
- CVE-2019-1674839İzleyin
In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking.
KritikCVSS 9,8İstismar yokEPSS %1wolfssl · wolfssl24 Eyl 2019
- CVE-2019-1565139İzleyin
wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte
KritikCVSS 9,8İstismar yokEPSS %1wolfssl · wolfssl26 Ağu 2019
- CVE-2022-4290537İzleyin
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network atta
KritikCVSS 9,1İstismar yokEPSS %2wolfssl · wolfssl6 Kas 2022
- CVE-2026-519437İzleyin
wolfSSL ECDSA Certificate Verification
KritikCVSS 9,3İstismar yokEPSS %0wolfssl · wolfssl9 Nis 2026
- CVE-2022-2340836İzleyin
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations.
KritikCVSS 9,1İstismar yokEPSS %1wolfssl · wolfssl18 Oca 2022
- CVE-2024-090136İzleyin
SEGV and out of bounds memory read from malicious packet
KritikCVSS 9,1İstismar yokEPSS %1wolfssl · wolfssl25 Mar 2024
- CVE-2023-693636İzleyin
Heap-buffer over-read with WOLFSSL_CALLBACKS
KritikCVSS 9,1İstismar yokEPSS %1wolfssl · wolfssl20 Şub 2024
- CVE-2023-372435İzleyin
TLS 1.3 client issue handling malicious server when not including a KSE and PSK extension
YüksekCVSS 8,8İstismar yokEPSS %1wolfssl · wolfssl17 Tem 2023
- CVE-2024-154535İzleyin
Fault Injection of RSA encryption in WolfCrypt
YüksekCVSS 8,8İstismar yokEPSS %1wolfssl · wolfssl29 Ağu 2024
- CVE-2026-667935İzleyin
DTLS 1.3 ACK serialization heap buffer overflow via integer truncation
YüksekCVSS 8,8İstismar yokEPSS %1wolfssl · wolfssl25 Haz 2026
- CVE-2024-288135İzleyin
Fault Injection of EdDSA signature in WolfCrypt
YüksekCVSS 8,8İstismar yokEPSS %0wolfssl · wolfssl29 Ağu 2024
- CVE-2026-550034İzleyin
Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass
YüksekCVSS 8,7İstismar yokEPSS %0wolfssl · wolfssl10 Nis 2026
- CVE-2026-1131034İzleyin
X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
YüksekCVSS 8,7İstismar yokEPSS %0wolfssl · wolfssl25 Haz 2026
- CVE-2026-550134İzleyin
Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates
YüksekCVSS 8,6İstismar yokEPSS %0wolfssl · wolfssl10 Nis 2026
- CVE-2026-526433İzleyin
DTLS 1.3 ACK heap buffer overflow
YüksekCVSS 8,3İstismar yokEPSS %1wolfssl · wolfssl9 Nis 2026