matrixssl records
24 published records for vendor matrixssl.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 4.2%
- Pre-auth RCE
- 5
- With a fix record
- 4.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-125 Out-of-bounds Read3
- CWE-190 Integer Overflow or Wraparound3
- CWE-787 Out-of-bounds Write3
- CWE-295 Improper Certificate Validation3
- CWE-416 Use After Free2
The weakness classes this vendor ships most often: where to look.
CWEAll records
24 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2016-6890No exploit | Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an matrixssl · matrixssl · CWE-119 | Critical9.8 | — | 6.4% | Jan 5, 2017 |
40Plan | CVE-2019-14431No exploit | In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of matrixssl · matrixssl · CWE-755 | Critical9.8 | — | 3.6% | Jul 29, 2019 |
40Plan | CVE-2017-2780No exploit | An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.matrixssl · matrixssl · CWE-787 | Critical9.8 | — | 2.3% | Jun 22, 2017 |
40Plan | CVE-2017-2781No exploit | An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.matrixssl · matrixssl · CWE-787 | Critical9.8 | — | 2.3% | Jun 22, 2017 |
40Plan | CVE-2022-43974No exploit | MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13.matrixssl · matrixssl · CWE-190 | Critical9.8 | — | 1.7% | Jan 9, 2023 |
39Monitor | CVE-2019-13470No exploit | MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.matrixssl · matrixssl · CWE-125 | Critical9.8 | — | 1.6% | Jul 9, 2019 |
39Monitor | CVE-2019-10914No exploit | pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 matrixssl · matrixssl · CWE-295 | Critical9.8 | — | 1.4% | Apr 8, 2019 |
36Monitor | CVE-2017-2782No exploit | An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.matrixssl · matrixssl · CWE-190 | Critical9.1 | — | 1.0% | Jun 22, 2017 |
31Monitor | CVE-2016-6892No exploit | The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory) matrixssl · matrixssl · CWE-416 | High7.5 | — | 1.9% | Jan 5, 2017 |
31Monitor | CVE-2016-6891No exploit | MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in matrixssl · matrixssl · CWE-125 | High7.5 | — | 1.9% | Jan 5, 2017 |
31Monitor | CVE-2019-16747No exploit | In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via matrixssl · matrixssl · CWE-787 | High7.5 | — | 1.8% | Dec 30, 2020 |
31Monitor | CVE-2016-6886No exploit | The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) viamatrixssl · matrixssl · CWE-320 | High7.5 | — | 1.7% | Jan 13, 2017 |
30Monitor | CVE-2016-6885No exploit | The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a basematrixssl · matrixssl · CWE-416 | High7.5 | — | 1.3% | Jan 13, 2017 |
30Monitor | CVE-2022-46505Proof of concept | An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero matrixssl · matrixssl · CWE-665 | High7.5 | — | 0.9% | Jan 18, 2023 |
30Monitor | CVE-2023-24609No exploit | Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parrambus · tls toolkit · CWE-190 | High7.5 | — | 0.7% | Dec 22, 2023 |
27Monitor | CVE-2016-6883Weaponized | MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher varianmatrixssl · matrixssl · CWE-200 | Medium5.9 | — | 13.9% | Mar 3, 2017 |
26Monitor | CVE-2016-6884No exploit | TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-boumatrixssl · matrixssl · CWE-125 | Medium6.5 | — | 1.3% | Mar 3, 2017 |
23Monitor | CVE-2016-8671No exploit | The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackermatrixssl · matrixssl · CWE-200 | Medium5.9 | — | 1.3% | Jan 13, 2017 |
23Monitor | CVE-2016-6882No exploit | MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key infmatrixssl · matrixssl · CWE-200 | Medium5.9 | — | 1.3% | Mar 3, 2017 |
23Monitor | CVE-2019-13629No exploit | MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.matrixssl · matrixssl · CWE-203 | Medium5.9 | — | 1.2% | Oct 3, 2019 |
23Monitor | CVE-2016-6887No exploit | The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackermatrixssl · matrixssl · CWE-200 | Medium5.9 | — | 1.2% | Jan 13, 2017 |
23Monitor | CVE-2017-1000415No exploit | MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certifimatrixssl · matrixssl · CWE-295 | Medium5.9 | — | 0.5% | Jan 9, 2018 |
21Monitor | CVE-2017-1000417No exploit | MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g.matrixssl · matrixssl · CWE-295 | Medium5.3 | — | 0.6% | Jan 22, 2018 |
18Monitor | CVE-2018-12439No exploit | MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or Rmatrixssl · matrixssl · CWE-200 | Medium4.7 | — | 0.3% | Jun 14, 2018 |
- CVE-2016-689041Plan
Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an
CriticalCVSS 9.8No exploitEPSS 6%matrixssl · matrixsslJan 5, 2017
- CVE-2019-1443140Plan
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of
CriticalCVSS 9.8No exploitEPSS 4%matrixssl · matrixsslJul 29, 2019
- CVE-2017-278040Plan
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
CriticalCVSS 9.8No exploitEPSS 2%matrixssl · matrixsslJun 22, 2017
- CVE-2017-278140Plan
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
CriticalCVSS 9.8No exploitEPSS 2%matrixssl · matrixsslJun 22, 2017
- CVE-2022-4397440Plan
MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13.
CriticalCVSS 9.8No exploitEPSS 2%matrixssl · matrixsslJan 9, 2023
- CVE-2019-1347039Monitor
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
CriticalCVSS 9.8No exploitEPSS 2%matrixssl · matrixsslJul 9, 2019
- CVE-2019-1091439Monitor
pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509
CriticalCVSS 9.8No exploitEPSS 1%matrixssl · matrixsslApr 8, 2019
- CVE-2017-278236Monitor
An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
CriticalCVSS 9.1No exploitEPSS 1%matrixssl · matrixsslJun 22, 2017
- CVE-2016-689231Monitor
The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory)
HighCVSS 7.5No exploitEPSS 2%matrixssl · matrixsslJan 5, 2017
- CVE-2016-689131Monitor
MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in
HighCVSS 7.5No exploitEPSS 2%matrixssl · matrixsslJan 5, 2017
- CVE-2019-1674731Monitor
In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via
HighCVSS 7.5No exploitEPSS 2%matrixssl · matrixsslDec 30, 2020
- CVE-2016-688631Monitor
The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via
HighCVSS 7.5No exploitEPSS 2%matrixssl · matrixsslJan 13, 2017
- CVE-2016-688530Monitor
The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base
HighCVSS 7.5No exploitEPSS 1%matrixssl · matrixsslJan 13, 2017
- CVE-2022-4650530Monitor
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero
HighCVSS 7.5Proof of conceptEPSS 1%matrixssl · matrixsslJan 18, 2023
- CVE-2023-2460930Monitor
Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension par
HighCVSS 7.5No exploitEPSS 1%rambus · tls toolkitDec 22, 2023
- CVE-2016-688327Monitor
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher varian
MediumCVSS 5.9WeaponizedEPSS 14%matrixssl · matrixsslMar 3, 2017
- CVE-2016-688426Monitor
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bou
MediumCVSS 6.5No exploitEPSS 1%matrixssl · matrixsslMar 3, 2017
- CVE-2016-867123Monitor
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attacker
MediumCVSS 5.9No exploitEPSS 1%matrixssl · matrixsslJan 13, 2017
- CVE-2016-688223Monitor
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key inf
MediumCVSS 5.9No exploitEPSS 1%matrixssl · matrixsslMar 3, 2017
- CVE-2019-1362923Monitor
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.
MediumCVSS 5.9No exploitEPSS 1%matrixssl · matrixsslOct 3, 2019
- CVE-2016-688723Monitor
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attacker
MediumCVSS 5.9No exploitEPSS 1%matrixssl · matrixsslJan 13, 2017
- CVE-2017-100041523Monitor
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certifi
MediumCVSS 5.9No exploitEPSS 0%matrixssl · matrixsslJan 9, 2018
- CVE-2017-100041721Monitor
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g.
MediumCVSS 5.3No exploitEPSS 1%matrixssl · matrixsslJan 22, 2018
- CVE-2018-1243918Monitor
MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or R
MediumCVSS 4.7No exploitEPSS 0%matrixssl · matrixsslJun 14, 2018