Skip to content
Noroxi

erlang records

46 published records for vendor erlang.

All records

46 records
  • Erlang/OTP SSH Vulnerable to Pre-Authentication RCE

    CriticalCVSS 10.0KEVWeaponizedEPSS 99%

    erlang · erlang\/otpApr 16, 2025

  • The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas

    MediumCVSS 5.9Proof of conceptEPSS 93%

    ssh · sshDec 18, 2023

  • Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.

    CriticalCVSS 9.8No exploitEPSS 7%

    erlang · rebar3Sep 2, 2020

  • An issue was discovered in Erlang/OTP 18.x.

    CriticalCVSS 9.8No exploitEPSS 1%

    erlang · erlang\/otpMar 18, 2017

  • In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-cert

    CriticalCVSS 9.8No exploitEPSS 1%

    erlang · erlang\/otpSep 21, 2022

  • Erlang/OTP Rebar3 version 3.7.0 through 3.7.5 contains a Signing oracle vulnerability in Package registry verification that can result in Pa

    HighCVSS 8.8No exploitEPSS 2%

    erlang · rebar3Feb 4, 2019

  • TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication

    CriticalCVSS 9.1No exploitEPSS 0%

    erlang · erlang\/otpJul 27, 2026

  • Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash

    HighCVSS 8.8No exploitEPSS 1%

    erlang · erlang\/otpJun 10, 2026

  • DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions

    HighCVSS 8.7No exploitEPSS 1%

    erlang · erlang\/otpJul 2, 2026

  • TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain

    HighCVSS 8.7No exploitEPSS 1%

    erlang · erlang\/otpJul 27, 2026

  • Denial of service via exponential certificate policy tree growth in path validation

    HighCVSS 8.7No exploitEPSS 1%

    erlang · erlang\/otpJul 27, 2026

  • ScriptAlias CGI targets bypass directory auth in inets httpd (mod_auth vs mod_cgi path mismatch)

    HighCVSS 8.3No exploitEPSS 1%

    erlang · erlang\/inetsApr 7, 2026

  • CVE-2011-0766
    32Monitor

    The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14

    HighCVSS 7.8No exploitEPSS 3%

    erlang · cryptoMay 31, 2011

  • TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension

    HighCVSS 8.2No exploitEPSS 1%

    erlang · erlang\/otpJul 2, 2026

  • BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding

    HighCVSS 8.2No exploitEPSS 1%

    erlang · erlang\/otpJul 27, 2026

  • Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal.

    HighCVSS 7.5No exploitEPSS 3%

    erlang · erlang\/otpOct 2, 2020

  • CVE-2014-1693
    31Monitor

    Multiple CRLF injection vulnerabilities in the FTP module in Erlang/OTP R15B03 allow context-dependent attackers to inject arbitrary FTP com

    HighCVSS 7.5No exploitEPSS 2%

    erlang · erlang\/otpDec 8, 2014

  • The Erlang otp TLS server answers with different TLS alerts to different error types in the RSA PKCS #1 1.5 padding.

    MediumCVSS 5.9WeaponizedEPSS 22%

    erlang · erlang\/otpDec 12, 2017

  • CVE-2009-0130
    30Monitor

    lib/crypto/c_src/crypto_drv.c in erlang does not properly check the return value from the OpenSSL DSA_do_verify function, which might allow

    HighCVSS 7.5No exploitEPSS 1%

    erlang · erlangJan 15, 2009

  • An issue was discovered in Erlang/OTP before 23.2.2.

    HighCVSS 7.5No exploitEPSS 1%

    erlang · erlang\/otpJan 15, 2021

  • nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verification

    HighCVSS 7.6No exploitEPSS 0%

    erlang · erlang\/otpMay 27, 2026

  • Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist

    HighCVSS 7.5No exploitEPSS 0%

    erlang · erlang\/otpJun 10, 2026

  • OCSP designated-responder authorization bypass via missing signature verification

    HighCVSS 7.6No exploitEPSS 0%

    erlang · erlang\/otpApr 7, 2026

  • A local privilege escalation vulnerability was discovered in Erlang/OTP prior to version 23.2.3.

    HighCVSS 7.0No exploitEPSS 1%

    erlang · erlang\/otpApr 9, 2021

  • httpc leaks Authorization header to cross-origin redirect targets

    HighCVSS 7.1No exploitEPSS 1%

    erlang · erlang\/inetsJun 10, 2026