Skip to content
Noroxi

matrixssl records

24 published records for vendor matrixssl.

Researcher profile

Entered KEV
0 · 0%
Weaponized
1 · 4.2%
Pre-auth RCE
5
With a fix record
4.2%
Median publish → KEV
No record has entered KEV

All records

24 records
  • Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an

    CriticalCVSS 9.8No exploitEPSS 6%

    matrixssl · matrixsslJan 5, 2017

  • In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of

    CriticalCVSS 9.8No exploitEPSS 4%

    matrixssl · matrixsslJul 29, 2019

  • An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.

    CriticalCVSS 9.8No exploitEPSS 2%

    matrixssl · matrixsslJun 22, 2017

  • An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.

    CriticalCVSS 9.8No exploitEPSS 2%

    matrixssl · matrixsslJun 22, 2017

  • MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13.

    CriticalCVSS 9.8No exploitEPSS 2%

    matrixssl · matrixsslJan 9, 2023

  • MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.

    CriticalCVSS 9.8No exploitEPSS 2%

    matrixssl · matrixsslJul 9, 2019

  • pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509

    CriticalCVSS 9.8No exploitEPSS 1%

    matrixssl · matrixsslApr 8, 2019

  • CVE-2017-2782
    36Monitor

    An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.

    CriticalCVSS 9.1No exploitEPSS 1%

    matrixssl · matrixsslJun 22, 2017

  • CVE-2016-6892
    31Monitor

    The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory)

    HighCVSS 7.5No exploitEPSS 2%

    matrixssl · matrixsslJan 5, 2017

  • CVE-2016-6891
    31Monitor

    MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in

    HighCVSS 7.5No exploitEPSS 2%

    matrixssl · matrixsslJan 5, 2017

  • In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via

    HighCVSS 7.5No exploitEPSS 2%

    matrixssl · matrixsslDec 30, 2020

  • CVE-2016-6886
    31Monitor

    The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via

    HighCVSS 7.5No exploitEPSS 2%

    matrixssl · matrixsslJan 13, 2017

  • CVE-2016-6885
    30Monitor

    The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base

    HighCVSS 7.5No exploitEPSS 1%

    matrixssl · matrixsslJan 13, 2017

  • An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero

    HighCVSS 7.5Proof of conceptEPSS 1%

    matrixssl · matrixsslJan 18, 2023

  • Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension par

    HighCVSS 7.5No exploitEPSS 1%

    rambus · tls toolkitDec 22, 2023

  • CVE-2016-6883
    27Monitor

    MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher varian

    MediumCVSS 5.9WeaponizedEPSS 14%

    matrixssl · matrixsslMar 3, 2017

  • CVE-2016-6884
    26Monitor

    TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bou

    MediumCVSS 6.5No exploitEPSS 1%

    matrixssl · matrixsslMar 3, 2017

  • CVE-2016-8671
    23Monitor

    The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attacker

    MediumCVSS 5.9No exploitEPSS 1%

    matrixssl · matrixsslJan 13, 2017

  • CVE-2016-6882
    23Monitor

    MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key inf

    MediumCVSS 5.9No exploitEPSS 1%

    matrixssl · matrixsslMar 3, 2017

  • MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.

    MediumCVSS 5.9No exploitEPSS 1%

    matrixssl · matrixsslOct 3, 2019

  • CVE-2016-6887
    23Monitor

    The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attacker

    MediumCVSS 5.9No exploitEPSS 1%

    matrixssl · matrixsslJan 13, 2017

  • MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certifi

    MediumCVSS 5.9No exploitEPSS 0%

    matrixssl · matrixsslJan 9, 2018

  • MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g.

    MediumCVSS 5.3No exploitEPSS 1%

    matrixssl · matrixsslJan 22, 2018

  • MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or R

    MediumCVSS 4.7No exploitEPSS 0%

    matrixssl · matrixsslJun 14, 2018