Vulnerability index

Browse CVEs

133 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wolfssl CRITICAL 9.8
CVE-2019-15651

wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is misha…

Mitigation only
Fix from $2,300 2019-08-26
Wolfssl CRITICAL 9.8
CVE-2019-11873EPSS 9%

wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker se…

Patch available
Fix from $2,300 2019-05-23
Wolfssl CRITICAL 9.8
CVE-2019-6439

examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.

Fix: after 3.15.7
Fix from $2,300 2019-01-16
Wolfssl MEDIUM 5.9
CVE-2018-16870

It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This ma…

Fix: 3.15.7+
Fix from $1,600 2019-01-03
Wolfssl MEDIUM 5.9
CVE-2017-13099EPSS 25%

wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can…

Fix: 3.12.2 / 6.5.4.6+
Fix from $1,600 2017-12-13
Wolfssl MEDIUM 5.9
CVE-2014-2903

CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate n…

Fix: after 2.9.4
Fix from $1,600 2017-10-06
Wolfssl CRITICAL 9.8
CVE-2017-2800EPSS 9%

A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate val…

Fix: after 3.10.2
Fix from $2,300 2017-05-24
Wolfssl HIGH 7.8
CVE-2017-8854

wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, aka a buffer overflow triggered by a malformed temporary…

Fix: after 3.10.0a
Fix from $1,950 2017-05-09
Wolfssl HIGH 7.5
CVE-2017-8855

wolfSSL before 3.11.0 does not prevent wc_DhAgree from accepting a malformed DH key.

Fix: after 3.10.4
Fix from $1,950 2017-05-09
Wolfssl MEDIUM 5.5
CVE-2017-6076

In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to …

Fix: 3.10.2+
Fix from $1,600 2017-02-24
Wolfssl MEDIUM 5.5
CVE-2016-7439

The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging ca…

Fix: after 3.9.8
Fix from $1,600 2016-12-13
Wolfssl MEDIUM 5.5
CVE-2016-7438

The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging ca…

Fix: after 3.9.8
Fix from $1,600 2016-12-13
Wolfssl HIGH 7.5
CVE-2015-6925

wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a cra…

Fix: after 3.6.6
Fix from $1,950 2016-01-22