matrixssl kayıtları
matrixssl üreticisine ait 24 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %4,2
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %4,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-125 Out-of-bounds Read3
- CWE-190 Integer Overflow or Wraparound3
- CWE-787 Out-of-bounds Write3
- CWE-295 Improper Certificate Validation3
- CWE-416 Use After Free2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
24 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2016-6890İstismar yok | Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an matrixssl · matrixssl · CWE-119 | Kritik9,8 | — | %6,4 | 5 Oca 2017 |
40Planlayın | CVE-2019-14431İstismar yok | In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of matrixssl · matrixssl · CWE-755 | Kritik9,8 | — | %3,6 | 29 Tem 2019 |
40Planlayın | CVE-2017-2780İstismar yok | An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.matrixssl · matrixssl · CWE-787 | Kritik9,8 | — | %2,3 | 22 Haz 2017 |
40Planlayın | CVE-2017-2781İstismar yok | An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.matrixssl · matrixssl · CWE-787 | Kritik9,8 | — | %2,3 | 22 Haz 2017 |
40Planlayın | CVE-2022-43974İstismar yok | MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13.matrixssl · matrixssl · CWE-190 | Kritik9,8 | — | %1,7 | 9 Oca 2023 |
39İzleyin | CVE-2019-13470İstismar yok | MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.matrixssl · matrixssl · CWE-125 | Kritik9,8 | — | %1,6 | 9 Tem 2019 |
39İzleyin | CVE-2019-10914İstismar yok | pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 matrixssl · matrixssl · CWE-295 | Kritik9,8 | — | %1,4 | 8 Nis 2019 |
36İzleyin | CVE-2017-2782İstismar yok | An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.matrixssl · matrixssl · CWE-190 | Kritik9,1 | — | %1,0 | 22 Haz 2017 |
31İzleyin | CVE-2016-6892İstismar yok | The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory) matrixssl · matrixssl · CWE-416 | Yüksek7,5 | — | %1,9 | 5 Oca 2017 |
31İzleyin | CVE-2016-6891İstismar yok | MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in matrixssl · matrixssl · CWE-125 | Yüksek7,5 | — | %1,9 | 5 Oca 2017 |
31İzleyin | CVE-2019-16747İstismar yok | In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via matrixssl · matrixssl · CWE-787 | Yüksek7,5 | — | %1,8 | 30 Ara 2020 |
31İzleyin | CVE-2016-6886İstismar yok | The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) viamatrixssl · matrixssl · CWE-320 | Yüksek7,5 | — | %1,7 | 13 Oca 2017 |
30İzleyin | CVE-2016-6885İstismar yok | The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a basematrixssl · matrixssl · CWE-416 | Yüksek7,5 | — | %1,3 | 13 Oca 2017 |
30İzleyin | CVE-2022-46505Kavram kanıtı | An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero matrixssl · matrixssl · CWE-665 | Yüksek7,5 | — | %0,9 | 18 Oca 2023 |
30İzleyin | CVE-2023-24609İstismar yok | Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parrambus · tls toolkit · CWE-190 | Yüksek7,5 | — | %0,7 | 22 Ara 2023 |
27İzleyin | CVE-2016-6883Silahlaştırılmış | MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher varianmatrixssl · matrixssl · CWE-200 | Orta5,9 | — | %13,9 | 3 Mar 2017 |
26İzleyin | CVE-2016-6884İstismar yok | TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-boumatrixssl · matrixssl · CWE-125 | Orta6,5 | — | %1,3 | 3 Mar 2017 |
23İzleyin | CVE-2016-8671İstismar yok | The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackermatrixssl · matrixssl · CWE-200 | Orta5,9 | — | %1,3 | 13 Oca 2017 |
23İzleyin | CVE-2016-6882İstismar yok | MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key infmatrixssl · matrixssl · CWE-200 | Orta5,9 | — | %1,3 | 3 Mar 2017 |
23İzleyin | CVE-2019-13629İstismar yok | MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.matrixssl · matrixssl · CWE-203 | Orta5,9 | — | %1,2 | 3 Eki 2019 |
23İzleyin | CVE-2016-6887İstismar yok | The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackermatrixssl · matrixssl · CWE-200 | Orta5,9 | — | %1,2 | 13 Oca 2017 |
23İzleyin | CVE-2017-1000415İstismar yok | MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certifimatrixssl · matrixssl · CWE-295 | Orta5,9 | — | %0,5 | 9 Oca 2018 |
21İzleyin | CVE-2017-1000417İstismar yok | MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g.matrixssl · matrixssl · CWE-295 | Orta5,3 | — | %0,6 | 22 Oca 2018 |
18İzleyin | CVE-2018-12439İstismar yok | MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or Rmatrixssl · matrixssl · CWE-200 | Orta4,7 | — | %0,3 | 14 Haz 2018 |
- CVE-2016-689041Planlayın
Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an
KritikCVSS 9,8İstismar yokEPSS %6matrixssl · matrixssl5 Oca 2017
- CVE-2019-1443140Planlayın
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of
KritikCVSS 9,8İstismar yokEPSS %4matrixssl · matrixssl29 Tem 2019
- CVE-2017-278040Planlayın
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
KritikCVSS 9,8İstismar yokEPSS %2matrixssl · matrixssl22 Haz 2017
- CVE-2017-278140Planlayın
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
KritikCVSS 9,8İstismar yokEPSS %2matrixssl · matrixssl22 Haz 2017
- CVE-2022-4397440Planlayın
MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13.
KritikCVSS 9,8İstismar yokEPSS %2matrixssl · matrixssl9 Oca 2023
- CVE-2019-1347039İzleyin
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
KritikCVSS 9,8İstismar yokEPSS %2matrixssl · matrixssl9 Tem 2019
- CVE-2019-1091439İzleyin
pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509
KritikCVSS 9,8İstismar yokEPSS %1matrixssl · matrixssl8 Nis 2019
- CVE-2017-278236İzleyin
An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
KritikCVSS 9,1İstismar yokEPSS %1matrixssl · matrixssl22 Haz 2017
- CVE-2016-689231İzleyin
The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory)
YüksekCVSS 7,5İstismar yokEPSS %2matrixssl · matrixssl5 Oca 2017
- CVE-2016-689131İzleyin
MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in
YüksekCVSS 7,5İstismar yokEPSS %2matrixssl · matrixssl5 Oca 2017
- CVE-2019-1674731İzleyin
In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via
YüksekCVSS 7,5İstismar yokEPSS %2matrixssl · matrixssl30 Ara 2020
- CVE-2016-688631İzleyin
The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via
YüksekCVSS 7,5İstismar yokEPSS %2matrixssl · matrixssl13 Oca 2017
- CVE-2016-688530İzleyin
The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base
YüksekCVSS 7,5İstismar yokEPSS %1matrixssl · matrixssl13 Oca 2017
- CVE-2022-4650530İzleyin
An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero
YüksekCVSS 7,5Kavram kanıtıEPSS %1matrixssl · matrixssl18 Oca 2023
- CVE-2023-2460930İzleyin
Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension par
YüksekCVSS 7,5İstismar yokEPSS %1rambus · tls toolkit22 Ara 2023
- CVE-2016-688327İzleyin
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher varian
OrtaCVSS 5,9SilahlaştırılmışEPSS %14matrixssl · matrixssl3 Mar 2017
- CVE-2016-688426İzleyin
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bou
OrtaCVSS 6,5İstismar yokEPSS %1matrixssl · matrixssl3 Mar 2017
- CVE-2016-867123İzleyin
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attacker
OrtaCVSS 5,9İstismar yokEPSS %1matrixssl · matrixssl13 Oca 2017
- CVE-2016-688223İzleyin
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key inf
OrtaCVSS 5,9İstismar yokEPSS %1matrixssl · matrixssl3 Mar 2017
- CVE-2019-1362923İzleyin
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.
OrtaCVSS 5,9İstismar yokEPSS %1matrixssl · matrixssl3 Eki 2019
- CVE-2016-688723İzleyin
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attacker
OrtaCVSS 5,9İstismar yokEPSS %1matrixssl · matrixssl13 Oca 2017
- CVE-2017-100041523İzleyin
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certifi
OrtaCVSS 5,9İstismar yokEPSS %0matrixssl · matrixssl9 Oca 2018
- CVE-2017-100041721İzleyin
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g.
OrtaCVSS 5,3İstismar yokEPSS %1matrixssl · matrixssl22 Oca 2018
- CVE-2018-1243918İzleyin
MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or R
OrtaCVSS 4,7İstismar yokEPSS %0matrixssl · matrixssl14 Haz 2018