Skip to content
Noroxi

wolfSSL records

153 published records for vendor wolfssl.

Researcher profile

Entered KEV
0 · 0%
Weaponized
2 · 1.3%
Pre-auth RCE
3
With a fix record
68.4%
Median publish → KEV
No record has entered KEV

All records

153 records
  • Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysq

    HighCVSS 7.5WeaponizedEPSS 70%

    oracle · mysqlDec 30, 2009

  • wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size.

    CriticalCVSS 9.8No exploitEPSS 9%

    wolfssl · wolfsslMay 23, 2019

  • A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certif

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    wolfssl · wolfsslMay 24, 2017

  • RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest s

    CriticalCVSS 9.8No exploitEPSS 4%

    wolfssl · wolfsslJan 6, 2021

  • The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified

    CriticalCVSS 9.8No exploitEPSS 3%

    wolfssl · wolfsslJan 28, 2020

  • The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows re

    CriticalCVSS 9.8No exploitEPSS 3%

    wolfssl · wolfsslJan 28, 2020

  • wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers

    CriticalCVSS 9.8No exploitEPSS 3%

    wolfssl · wolfsslJan 28, 2020

  • examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.

    CriticalCVSS 9.8No exploitEPSS 3%

    wolfssl · wolfsslJan 15, 2019

  • Buffer overread in domain name matching

    CriticalCVSS 10.0No exploitEPSS 1%

    wolfssl · wolfsslAug 27, 2024

  • wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the seria

    CriticalCVSS 9.8No exploitEPSS 1%

    wolfssl · wolfsslJul 21, 2021

  • In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking.

    CriticalCVSS 9.8No exploitEPSS 1%

    wolfssl · wolfsslSep 24, 2019

  • wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte

    CriticalCVSS 9.8No exploitEPSS 1%

    wolfssl · wolfsslAug 26, 2019

  • In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network atta

    CriticalCVSS 9.1No exploitEPSS 2%

    wolfssl · wolfsslNov 6, 2022

  • CVE-2026-5194
    37Monitor

    wolfSSL ECDSA Certificate Verification

    CriticalCVSS 9.3No exploitEPSS 0%

    wolfssl · wolfsslApr 9, 2026

  • wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations.

    CriticalCVSS 9.1No exploitEPSS 1%

    wolfssl · wolfsslJan 18, 2022

  • CVE-2024-0901
    36Monitor

    SEGV and out of bounds memory read from malicious packet

    CriticalCVSS 9.1No exploitEPSS 1%

    wolfssl · wolfsslMar 25, 2024

  • CVE-2023-6936
    36Monitor

    Heap-buffer over-read with WOLFSSL_CALLBACKS

    CriticalCVSS 9.1No exploitEPSS 1%

    wolfssl · wolfsslFeb 20, 2024

  • CVE-2023-3724
    35Monitor

    TLS 1.3 client issue handling malicious server when not including a KSE and PSK extension

    HighCVSS 8.8No exploitEPSS 1%

    wolfssl · wolfsslJul 17, 2023

  • CVE-2024-1545
    35Monitor

    Fault Injection of RSA encryption in WolfCrypt

    HighCVSS 8.8No exploitEPSS 1%

    wolfssl · wolfsslAug 29, 2024

  • CVE-2026-6679
    35Monitor

    DTLS 1.3 ACK serialization heap buffer overflow via integer truncation

    HighCVSS 8.8No exploitEPSS 1%

    wolfssl · wolfsslJun 25, 2026

  • CVE-2024-2881
    35Monitor

    Fault Injection of EdDSA signature in WolfCrypt

    HighCVSS 8.8No exploitEPSS 0%

    wolfssl · wolfsslAug 29, 2024

  • CVE-2026-5500
    34Monitor

    Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass

    HighCVSS 8.7No exploitEPSS 0%

    wolfssl · wolfsslApr 10, 2026

  • X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring

    HighCVSS 8.7No exploitEPSS 0%

    wolfssl · wolfsslJun 25, 2026

  • CVE-2026-5501
    34Monitor

    Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates

    HighCVSS 8.6No exploitEPSS 0%

    wolfssl · wolfsslApr 10, 2026

  • CVE-2026-5264
    33Monitor

    DTLS 1.3 ACK heap buffer overflow

    HighCVSS 8.3No exploitEPSS 1%

    wolfssl · wolfsslApr 9, 2026