Записи wolfSSL
153 опубликованных записей вендора wolfssl.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 1,3 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 69,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-295 Improper Certificate Validation20
- CWE-787 Out-of-bounds Write16
- CWE-125 Out-of-bounds Read14
- CWE-203 Observable Discrepancy11
- CWE-122 Heap-based Buffer Overflow9
- CWE-20 Improper Input Validation8
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
153 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2009-4484Готовый эксплойт | Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqoracle · mysql · CWE-787 | Высокая7,5 | — | 69,6 % | 30 дек. 2009 г. |
42В плане | CVE-2019-11873Эксплойта нет | wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size.wolfssl · wolfssl · CWE-787 | Критическая9,8 | — | 8,8 % | 23 мая 2019 г. |
42В плане | CVE-2017-2800Proof of concept | A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certifwolfssl · wolfssl · CWE-295 | Критическая9,8 | — | 8,5 % | 24 мая 2017 г. |
40В плане | CVE-2020-36177Эксплойта нет | RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest swolfssl · wolfssl · CWE-787 | Критическая9,8 | — | 3,5 % | 6 янв. 2021 г. |
40В плане | CVE-2014-2896Эксплойта нет | The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified wolfssl · wolfssl · CWE-125 | Критическая9,8 | — | 2,8 % | 28 янв. 2020 г. |
40В плане | CVE-2014-2897Эксплойта нет | The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows rewolfssl · wolfssl · CWE-125 | Критическая9,8 | — | 2,8 % | 28 янв. 2020 г. |
40В плане | CVE-2014-2898Эксплойта нет | wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggerswolfssl · wolfssl · CWE-125 | Критическая9,8 | — | 2,8 % | 28 янв. 2020 г. |
40В плане | CVE-2019-6439Эксплойта нет | examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.wolfssl · wolfssl · CWE-787 | Критическая9,8 | — | 2,6 % | 15 янв. 2019 г. |
40В плане | CVE-2024-5991Эксплойта нет | Buffer overread in domain name matchingwolfssl · wolfssl · CWE-125 | Критическая10,0 | — | 0,6 % | 27 авг. 2024 г. |
39Наблюдать | CVE-2021-37155Эксплойта нет | wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the seriawolfssl · wolfssl | Критическая9,8 | — | 1,5 % | 21 июл. 2021 г. |
39Наблюдать | CVE-2019-16748Эксплойта нет | In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking.wolfssl · wolfssl · CWE-125 | Критическая9,8 | — | 1,2 % | 24 сент. 2019 г. |
39Наблюдать | CVE-2019-15651Эксплойта нет | wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN bytewolfssl · wolfssl · CWE-125 | Критическая9,8 | — | 1,0 % | 26 авг. 2019 г. |
37Наблюдать | CVE-2022-42905Эксплойта нет | In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attawolfssl · wolfssl · CWE-125 | Критическая9,1 | — | 2,1 % | 6 нояб. 2022 г. |
37Наблюдать | CVE-2026-5194Эксплойта нет | wolfSSL ECDSA Certificate Verificationwolfssl · wolfssl · CWE-295 | Критическая9,3 | — | 0,3 % | 9 апр. 2026 г. |
36Наблюдать | CVE-2022-23408Эксплойта нет | wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations.wolfssl · wolfssl · CWE-330 | Критическая9,1 | — | 1,4 % | 18 янв. 2022 г. |
36Наблюдать | CVE-2024-0901Эксплойта нет | SEGV and out of bounds memory read from malicious packetwolfssl · wolfssl · CWE-129 | Критическая9,1 | — | 0,7 % | 25 мар. 2024 г. |
36Наблюдать | CVE-2023-6936Эксплойта нет | Heap-buffer over-read with WOLFSSL_CALLBACKSwolfssl · wolfssl · CWE-125 | Критическая9,1 | — | 0,6 % | 20 февр. 2024 г. |
35Наблюдать | CVE-2023-3724Эксплойта нет | TLS 1.3 client issue handling malicious server when not including a KSE and PSK extensionwolfssl · wolfssl · CWE-20 | Высокая8,8 | — | 0,7 % | 17 июл. 2023 г. |
35Наблюдать | CVE-2024-1545Эксплойта нет | Fault Injection of RSA encryption in WolfCryptwolfssl · wolfssl · CWE-252 | Высокая8,8 | — | 0,6 % | 29 авг. 2024 г. |
35Наблюдать | CVE-2026-6679Эксплойта нет | DTLS 1.3 ACK serialization heap buffer overflow via integer truncationwolfssl · wolfssl · CWE-190 | Высокая8,8 | — | 0,5 % | 25 июн. 2026 г. |
35Наблюдать | CVE-2024-2881Эксплойта нет | Fault Injection of EdDSA signature in WolfCryptwolfssl · wolfssl · CWE-252 | Высокая8,8 | — | 0,5 % | 29 авг. 2024 г. |
34Наблюдать | CVE-2026-5500Эксплойта нет | Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypasswolfssl · wolfssl · CWE-20 | Высокая8,7 | — | 0,4 % | 10 апр. 2026 г. |
34Наблюдать | CVE-2026-11310Эксплойта нет | X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoringwolfssl · wolfssl · CWE-295 | Высокая8,7 | — | 0,2 % | 25 июн. 2026 г. |
34Наблюдать | CVE-2026-5501Эксплойта нет | Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificateswolfssl · wolfssl · CWE-295 | Высокая8,6 | — | 0,2 % | 10 апр. 2026 г. |
33Наблюдать | CVE-2026-5264Эксплойта нет | DTLS 1.3 ACK heap buffer overflowwolfssl · wolfssl · CWE-122 | Высокая8,3 | — | 0,6 % | 9 апр. 2026 г. |
- CVE-2009-448451В плане
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysq
ВысокаяCVSS 7,5Готовый эксплойтEPSS 70 %oracle · mysql30 дек. 2009 г.
- CVE-2019-1187342В плане
wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size.
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %wolfssl · wolfssl23 мая 2019 г.
- CVE-2017-280042В плане
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certif
КритическаяCVSS 9,8Proof of conceptEPSS 9 %wolfssl · wolfssl24 мая 2017 г.
- CVE-2020-3617740В плане
RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest s
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %wolfssl · wolfssl6 янв. 2021 г.
- CVE-2014-289640В плане
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %wolfssl · wolfssl28 янв. 2020 г.
- CVE-2014-289740В плане
The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows re
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %wolfssl · wolfssl28 янв. 2020 г.
- CVE-2014-289840В плане
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %wolfssl · wolfssl28 янв. 2020 г.
- CVE-2019-643940В плане
examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %wolfssl · wolfssl15 янв. 2019 г.
- CVE-2024-599140В плане
Buffer overread in domain name matching
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %wolfssl · wolfssl27 авг. 2024 г.
- CVE-2021-3715539Наблюдать
wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the seria
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wolfssl · wolfssl21 июл. 2021 г.
- CVE-2019-1674839Наблюдать
In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wolfssl · wolfssl24 сент. 2019 г.
- CVE-2019-1565139Наблюдать
wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %wolfssl · wolfssl26 авг. 2019 г.
- CVE-2022-4290537Наблюдать
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network atta
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %wolfssl · wolfssl6 нояб. 2022 г.
- CVE-2026-519437Наблюдать
wolfSSL ECDSA Certificate Verification
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %wolfssl · wolfssl9 апр. 2026 г.
- CVE-2022-2340836Наблюдать
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %wolfssl · wolfssl18 янв. 2022 г.
- CVE-2024-090136Наблюдать
SEGV and out of bounds memory read from malicious packet
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %wolfssl · wolfssl25 мар. 2024 г.
- CVE-2023-693636Наблюдать
Heap-buffer over-read with WOLFSSL_CALLBACKS
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %wolfssl · wolfssl20 февр. 2024 г.
- CVE-2023-372435Наблюдать
TLS 1.3 client issue handling malicious server when not including a KSE and PSK extension
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wolfssl · wolfssl17 июл. 2023 г.
- CVE-2024-154535Наблюдать
Fault Injection of RSA encryption in WolfCrypt
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wolfssl · wolfssl29 авг. 2024 г.
- CVE-2026-667935Наблюдать
DTLS 1.3 ACK serialization heap buffer overflow via integer truncation
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %wolfssl · wolfssl25 июн. 2026 г.
- CVE-2024-288135Наблюдать
Fault Injection of EdDSA signature in WolfCrypt
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %wolfssl · wolfssl29 авг. 2024 г.
- CVE-2026-550034Наблюдать
Improper Validation of AES-GCM Authentication Tag Length in PKCS#7 Envelope Allows Authentication Bypass
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %wolfssl · wolfssl10 апр. 2026 г.
- CVE-2026-1131034Наблюдать
X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %wolfssl · wolfssl25 июн. 2026 г.
- CVE-2026-550134Наблюдать
Improper Certificate Signature Verification in X.509 Chain Validation Allows Forged Leaf Certificates
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %wolfssl · wolfssl10 апр. 2026 г.
- CVE-2026-526433Наблюдать
DTLS 1.3 ACK heap buffer overflow
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %wolfssl · wolfssl9 апр. 2026 г.