openca records
4 published records for vendor openca.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2004-0004No exploit | The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and topenca · openca | High7.5 | — | 2.1% | Feb 17, 2004 |
30Monitor | CVE-2008-0556No exploit | Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unaopenca · openca pki · CWE-264 | High7.5 | — | 1.0% | Feb 18, 2008 |
30Monitor | CVE-2003-0960No exploit | OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expopenca · openca | High7.5 | — | 0.7% | Dec 15, 2003 |
17Monitor | CVE-2004-0787No exploit | Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackeopenca · openca | Medium4.3 | — | 1.2% | Oct 20, 2004 |
- CVE-2004-000431Monitor
The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and t
HighCVSS 7.5No exploitEPSS 2%openca · opencaFeb 17, 2004
- CVE-2008-055630Monitor
Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform una
HighCVSS 7.5No exploitEPSS 1%openca · openca pkiFeb 18, 2008
- CVE-2003-096030Monitor
OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or exp
HighCVSS 7.5No exploitEPSS 1%openca · opencaDec 15, 2003
- CVE-2004-078717Monitor
Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attacke
MediumCVSS 4.3No exploitEPSS 1%openca · opencaOct 20, 2004