axtls project kayıtları
axtls project üreticisine ait 8 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-347 Improper Verification of Cryptographic Signature3
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-787 Out-of-bounds Write2
- CWE-193 Off-by-one Error1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
8 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2019-8981İstismar yok | tls1.c in Cameron Hamilton-Rich axTLS before 2.1.5 has a Buffer Overflow via a crafted sequence of TLS packets because the need_bytes value axtls project · axtls · CWE-787 | Kritik9,8 | — | %2,7 | 25 Mar 2019 |
31İzleyin | CVE-2019-10013İstismar yok | The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cauaxtls project · axtls · CWE-120 | Yüksek7,5 | — | %1,9 | 3 Ara 2019 |
30İzleyin | CVE-2019-9689İstismar yok | process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certificate handshake mesaxtls project · axtls · CWE-120 | Yüksek7,5 | — | %1,5 | 3 Ara 2019 |
23İzleyin | CVE-2018-16149İstismar yok | In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification blindly trusts the declared lengths in taxtls project · axtls · CWE-347 | Orta5,9 | — | %0,7 | 7 Kas 2018 |
23İzleyin | CVE-2018-16253İstismar yok | In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not properly verify the ASN.1 metadaxtls project · axtls · CWE-347 | Orta5,9 | — | %0,6 | 7 Kas 2018 |
23İzleyin | CVE-2018-16150İstismar yok | In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not reject excess data after the haaxtls project · axtls · CWE-347 | Orta5,9 | — | %0,6 | 7 Kas 2018 |
22İzleyin | CVE-2023-33613İstismar yok | axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c.axtls project · axtls · CWE-787 | Orta5,5 | — | %0,3 | 6 Haz 2023 |
21İzleyin | CVE-2017-1000416İstismar yok | axTLS version 1.5.3 has a coding error in the ASN.1 parser resulting in the year (19)50 of UTCTime being misinterpreted as 2050.axtls project · axtls · CWE-193 | Orta5,3 | — | %0,9 | 22 Oca 2018 |
- CVE-2019-898140Planlayın
tls1.c in Cameron Hamilton-Rich axTLS before 2.1.5 has a Buffer Overflow via a crafted sequence of TLS packets because the need_bytes value
KritikCVSS 9,8İstismar yokEPSS %3axtls project · axtls25 Mar 2019
- CVE-2019-1001331İzleyin
The asn1_signature function in asn1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow that allows remote attackers to cau
YüksekCVSS 7,5İstismar yokEPSS %2axtls project · axtls3 Ara 2019
- CVE-2019-968930İzleyin
process_certificate in tls1.c in Cameron Hamilton-Rich axTLS through 2.1.5 has a Buffer Overflow via a crafted TLS certificate handshake mes
YüksekCVSS 7,5İstismar yokEPSS %1axtls project · axtls3 Ara 2019
- CVE-2018-1614923İzleyin
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification blindly trusts the declared lengths in t
OrtaCVSS 5,9İstismar yokEPSS %1axtls project · axtls7 Kas 2018
- CVE-2018-1625323İzleyin
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not properly verify the ASN.1 metad
OrtaCVSS 5,9İstismar yokEPSS %1axtls project · axtls7 Kas 2018
- CVE-2018-1615023İzleyin
In sig_verify() in x509.c in axTLS version 2.1.3 and before, the PKCS#1 v1.5 signature verification does not reject excess data after the ha
OrtaCVSS 5,9İstismar yokEPSS %1axtls project · axtls7 Kas 2018
- CVE-2023-3361322İzleyin
axTLS v2.1.5 was discovered to contain a heap buffer overflow in the bi_import function in axtls-code/crypto/bigint.c.
OrtaCVSS 5,5İstismar yokEPSS %0axtls project · axtls6 Haz 2023
- CVE-2017-100041621İzleyin
axTLS version 1.5.3 has a coding error in the ASN.1 parser resulting in the year (19)50 of UTCTime being misinterpreted as 2050.
OrtaCVSS 5,3İstismar yokEPSS %1axtls project · axtls22 Oca 2018