Vulnerability index

Browse CVEs

133 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wolfssl CRITICAL 9.1
CVE-2022-23408

wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connections (without AEAD) using AES-CBC or DES3 with TLS 1.1 …

Fix: 5.1.1+
Fix from $2,300 2022-01-18
Wolfmqtt MEDIUM 5.5
CVE-2021-45932

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (4 bytes) in MqttDecode_Publish (called from MqttClient_DecodePacket and MqttClient_HandlePacke…

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45933

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow (8 bytes) in MqttDecode_Publish (called from MqttClient_DecodePacket and MqttClient_HandlePacke…

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45934

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_HandlePacket and MqttClient_WaitType).

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45936

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttDecode_Disconnect (called from MqttClient_DecodePacket and MqttClient_WaitType).

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45937

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and MqttClient_Connect).

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45938

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and MqttClient_Unsubscribe).

Patch available
Fix from $1,600 2022-01-01
Wolfmqtt MEDIUM 5.5
CVE-2021-45939

wolfSSL wolfMQTT 1.9 has a heap-based buffer overflow in MqttClient_DecodePacket (called from MqttClient_WaitType and MqttClient_Subscribe).

Patch available
Fix from $1,600 2022-01-01
Wolfssl MEDIUM 5.9
CVE-2021-38597

wolfSSL before 4.8.1 incorrectly skips OCSP verification in certain situations of irrelevant response data that contains the NoCheck extension.

Fix: 4.8.1+
Fix from $1,600 2021-08-12
Wolfssl CRITICAL 9.8
CVE-2021-37155

wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial number in an OCSP request differs from the serial number …

Fix: 4.8.0+
Fix from $2,300 2021-07-21
Wolfssl HIGH 8.1
CVE-2021-3336

DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certain anomalous peer behavior (sending an ED22519, ED448,…

Fix: 4.7.0+
Fix from $1,950 2021-01-29
Wolfssl CRITICAL 9.8
CVE-2020-36177

RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certain relationships between key size and digest size.

Fix: 4.6.0+
Fix from $2,300 2021-01-06
Wolfssl MEDIUM 6.8
CVE-2020-24613

wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityCheckTls13MsgReceived() in tls13.c. This is an incorrect …

Fix: 4.5.0+
Fix from $1,600 2020-08-24
Wolfssl HIGH 7.0
CVE-2020-15309

An issue was discovered in wolfSSL before 4.5.0, when single precision is not employed. Local attackers can conduct a cache-timing attack against pub…

Fix: 4.5.0+
Fix from $1,950 2020-08-21
Wolfssl MEDIUM 5.3
CVE-2020-24585

An issue was discovered in the DTLS handshake implementation in wolfSSL before 4.5.0. Clear DTLS application_data messages in epoch 0 do not produce …

Fix: 4.5.0+
Fix from $1,600 2020-08-21
Wolfssl HIGH 7.5
CVE-2020-12457

An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) message processing logic for TLS 1.3. If an attacker send…

Fix: 4.5.0+
Fix from $1,950 2020-08-21
Wolfssl MEDIUM 5.3
CVE-2020-11735

The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular inverse when mapping to affine coordinates, aka a "pro…

Fix: 4.4.0+
Fix from $1,600 2020-06-25
Wolfssl HIGH 7.5
CVE-2020-11713

wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing side-channel attacks.

Patch available
Fix from $1,950 2020-04-12
Wolfssl CRITICAL 9.8
CVE-2014-2898

wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple calls to the CyaSSL_read function which triggers an out-o…

Fix: 2.9.0+
Fix from $2,300 2020-01-28
Wolfssl CRITICAL 9.8
CVE-2014-2896

The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact an…

Fix: 2.9.4+
Fix from $2,300 2020-01-28
Wolfssl CRITICAL 9.8
CVE-2014-2897

The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding length when verification fails, which allows remote atta…

Fix: 2.9.4+
Fix from $2,300 2020-01-28
Wolfssl HIGH 7.5
CVE-2019-19962

wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection in RSA cryptography.

Fix: 4.3.0+
Fix from $1,950 2019-12-25
Wolfssl MEDIUM 5.3
CVE-2019-19960

In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.

Fix: 4.3.0+
Fix from $1,600 2019-12-25
Wolfssl MEDIUM 5.3
CVE-2019-19963

An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is enabled. DSA signing uses the BEEA algorithm during modul…

Fix: 4.3.0+
Fix from $1,600 2019-12-25
Wolfssl MEDIUM 5.3
CVE-2019-14317

wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. This allows a remote attacker to compute the long term…

Fix: 4.2.0+
Fix from $1,600 2019-12-11
Wolfssl HIGH 7.5
CVE-2014-2901

wolfssl before 3.2.0 does not properly issue certificates for a server's hostname.

Fix: 3.2.0+
Fix from $1,950 2019-11-21
Wolfssl HIGH 7.5
CVE-2014-2902

wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.

Fix: 3.2.0+
Fix from $1,950 2019-11-21
Wolfssl HIGH 7.5
CVE-2014-2904

wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authentication.

Fix: 3.2.0+
Fix from $1,950 2019-11-21
Wolfssl HIGH 7.5
CVE-2019-18840

In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically…

Fix: after 4.2.0c
Fix from $1,950 2019-11-09
Wolfssl CRITICAL 9.8
CVE-2019-16748

In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 certificate data while handshaking. Specifically, there…

Fix: after 4.1.0
Fix from $2,300 2019-09-24