Записи matrixssl
24 опубликованных записей вендора matrixssl.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 4,2 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 4,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-125 Out-of-bounds Read3
- CWE-190 Integer Overflow or Wraparound3
- CWE-787 Out-of-bounds Write3
- CWE-295 Improper Certificate Validation3
- CWE-416 Use After Free2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
24 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2016-6890Эксплойта нет | Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an matrixssl · matrixssl · CWE-119 | Критическая9,8 | — | 6,4 % | 5 янв. 2017 г. |
40В плане | CVE-2019-14431Эксплойта нет | In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of matrixssl · matrixssl · CWE-755 | Критическая9,8 | — | 3,6 % | 29 июл. 2019 г. |
40В плане | CVE-2017-2780Эксплойта нет | An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.matrixssl · matrixssl · CWE-787 | Критическая9,8 | — | 2,3 % | 22 июн. 2017 г. |
40В плане | CVE-2017-2781Эксплойта нет | An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.matrixssl · matrixssl · CWE-787 | Критическая9,8 | — | 2,3 % | 22 июн. 2017 г. |
40В плане | CVE-2022-43974Эксплойта нет | MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13.matrixssl · matrixssl · CWE-190 | Критическая9,8 | — | 1,7 % | 9 янв. 2023 г. |
39Наблюдать | CVE-2019-13470Эксплойта нет | MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.matrixssl · matrixssl · CWE-125 | Критическая9,8 | — | 1,6 % | 9 июл. 2019 г. |
39Наблюдать | CVE-2019-10914Эксплойта нет | pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 matrixssl · matrixssl · CWE-295 | Критическая9,8 | — | 1,4 % | 8 апр. 2019 г. |
36Наблюдать | CVE-2017-2782Эксплойта нет | An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.matrixssl · matrixssl · CWE-190 | Критическая9,1 | — | 1,0 % | 22 июн. 2017 г. |
31Наблюдать | CVE-2016-6892Эксплойта нет | The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory) matrixssl · matrixssl · CWE-416 | Высокая7,5 | — | 1,9 % | 5 янв. 2017 г. |
31Наблюдать | CVE-2016-6891Эксплойта нет | MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in matrixssl · matrixssl · CWE-125 | Высокая7,5 | — | 1,9 % | 5 янв. 2017 г. |
31Наблюдать | CVE-2019-16747Эксплойта нет | In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via matrixssl · matrixssl · CWE-787 | Высокая7,5 | — | 1,8 % | 30 дек. 2020 г. |
31Наблюдать | CVE-2016-6886Эксплойта нет | The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) viamatrixssl · matrixssl · CWE-320 | Высокая7,5 | — | 1,7 % | 13 янв. 2017 г. |
30Наблюдать | CVE-2016-6885Эксплойта нет | The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a basematrixssl · matrixssl · CWE-416 | Высокая7,5 | — | 1,3 % | 13 янв. 2017 г. |
30Наблюдать | CVE-2022-46505Proof of concept | An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero matrixssl · matrixssl · CWE-665 | Высокая7,5 | — | 0,9 % | 18 янв. 2023 г. |
30Наблюдать | CVE-2023-24609Эксплойта нет | Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parrambus · tls toolkit · CWE-190 | Высокая7,5 | — | 0,7 % | 22 дек. 2023 г. |
27Наблюдать | CVE-2016-6883Готовый эксплойт | MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher varianmatrixssl · matrixssl · CWE-200 | Средняя5,9 | — | 13,9 % | 3 мар. 2017 г. |
26Наблюдать | CVE-2016-6884Эксплойта нет | TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-boumatrixssl · matrixssl · CWE-125 | Средняя6,5 | — | 1,3 % | 3 мар. 2017 г. |
23Наблюдать | CVE-2016-8671Эксплойта нет | The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackermatrixssl · matrixssl · CWE-200 | Средняя5,9 | — | 1,3 % | 13 янв. 2017 г. |
23Наблюдать | CVE-2016-6882Эксплойта нет | MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key infmatrixssl · matrixssl · CWE-200 | Средняя5,9 | — | 1,3 % | 3 мар. 2017 г. |
23Наблюдать | CVE-2019-13629Эксплойта нет | MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.matrixssl · matrixssl · CWE-203 | Средняя5,9 | — | 1,2 % | 3 окт. 2019 г. |
23Наблюдать | CVE-2016-6887Эксплойта нет | The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackermatrixssl · matrixssl · CWE-200 | Средняя5,9 | — | 1,2 % | 13 янв. 2017 г. |
23Наблюдать | CVE-2017-1000415Эксплойта нет | MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certifimatrixssl · matrixssl · CWE-295 | Средняя5,9 | — | 0,5 % | 9 янв. 2018 г. |
21Наблюдать | CVE-2017-1000417Эксплойта нет | MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g.matrixssl · matrixssl · CWE-295 | Средняя5,3 | — | 0,6 % | 22 янв. 2018 г. |
18Наблюдать | CVE-2018-12439Эксплойта нет | MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or Rmatrixssl · matrixssl · CWE-200 | Средняя4,7 | — | 0,3 % | 14 июн. 2018 г. |
- CVE-2016-689041В плане
Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %matrixssl · matrixssl5 янв. 2017 г.
- CVE-2019-1443140В плане
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %matrixssl · matrixssl29 июл. 2019 г.
- CVE-2017-278040В плане
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %matrixssl · matrixssl22 июн. 2017 г.
- CVE-2017-278140В плане
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %matrixssl · matrixssl22 июн. 2017 г.
- CVE-2022-4397440В плане
MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %matrixssl · matrixssl9 янв. 2023 г.
- CVE-2019-1347039Наблюдать
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %matrixssl · matrixssl9 июл. 2019 г.
- CVE-2019-1091439Наблюдать
pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %matrixssl · matrixssl8 апр. 2019 г.
- CVE-2017-278236Наблюдать
An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %matrixssl · matrixssl22 июн. 2017 г.
- CVE-2016-689231Наблюдать
The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory)
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrixssl · matrixssl5 янв. 2017 г.
- CVE-2016-689131Наблюдать
MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrixssl · matrixssl5 янв. 2017 г.
- CVE-2019-1674731Наблюдать
In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrixssl · matrixssl30 дек. 2020 г.
- CVE-2016-688631Наблюдать
The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %matrixssl · matrixssl13 янв. 2017 г.
- CVE-2016-688530Наблюдать
The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %matrixssl · matrixssl13 янв. 2017 г.
- CVE-2022-4650530Наблюдать
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %matrixssl · matrixssl18 янв. 2023 г.
- CVE-2023-2460930Наблюдать
Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension par
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %rambus · tls toolkit22 дек. 2023 г.
- CVE-2016-688327Наблюдать
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher varian
СредняяCVSS 5,9Готовый эксплойтEPSS 14 %matrixssl · matrixssl3 мар. 2017 г.
- CVE-2016-688426Наблюдать
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bou
СредняяCVSS 6,5Эксплойта нетEPSS 1 %matrixssl · matrixssl3 мар. 2017 г.
- CVE-2016-867123Наблюдать
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attacker
СредняяCVSS 5,9Эксплойта нетEPSS 1 %matrixssl · matrixssl13 янв. 2017 г.
- CVE-2016-688223Наблюдать
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key inf
СредняяCVSS 5,9Эксплойта нетEPSS 1 %matrixssl · matrixssl3 мар. 2017 г.
- CVE-2019-1362923Наблюдать
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %matrixssl · matrixssl3 окт. 2019 г.
- CVE-2016-688723Наблюдать
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attacker
СредняяCVSS 5,9Эксплойта нетEPSS 1 %matrixssl · matrixssl13 янв. 2017 г.
- CVE-2017-100041523Наблюдать
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certifi
СредняяCVSS 5,9Эксплойта нетEPSS 0 %matrixssl · matrixssl9 янв. 2018 г.
- CVE-2017-100041721Наблюдать
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %matrixssl · matrixssl22 янв. 2018 г.
- CVE-2018-1243918Наблюдать
MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or R
СредняяCVSS 4,7Эксплойта нетEPSS 0 %matrixssl · matrixssl14 июн. 2018 г.