Vulnerability index

Browse CVEs

133 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-2645 In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could incorrectly accept the Certif… Wolfssl 5.8.4+ Fix from $1,9502026-03-19 HIGH 7.1 CVE-2026-0819 A stack buffer overflow vulnerability exists in wolfSSL's PKCS7 SignedData encoding functionality. In wc_PKCS7_BuildSignedAttributes(), when adding c… Wolfssl 5.9.0+ Fix from $1,9502026-03-19 MEDIUM 5.3 CVE-2026-1005 Integer underflow in wolfSSL packet sniffer <= 5.8.4 allows an attacker to cause a buffer overflow in the AEAD decryption path by injecting a TLS rec… Wolfssl after 5.8.4 Fix from $1,6002026-03-19 MEDIUM 5.4 CVE-2025-12889 With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those in the CertificateRequest. Wolfssl Patch available Fix from $1,6002025-11-22 HIGH 7.5 CVE-2025-12888 Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler optimizations and CPU architec… Wolfssl Patch available Fix from $1,9502025-11-21 MEDIUM 6.5 CVE-2025-11933 Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows a remote unauthenticated att… Wolfssl 5.8.4+ Fix from $1,6002025-11-21 MEDIUM 5.3 CVE-2025-11936 Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to ca… Wolfssl 5.8.4+ Fix from $1,6002025-11-21 HIGH 8.2 CVE-2025-11931 Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a call to the function wc_XChaCha2… Wolfssl Patch available Fix from $1,9502025-11-21 HIGH 7.5 CVE-2025-11935 With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy) and the client would contin… Wolfssl 5.8.4+ Fix from $1,9502025-11-21 CRITICAL 9.8 CVE-2025-7394 In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable… Wolfssl after 5.8.0 Fix from $2,3002025-07-18 HIGH 8.8 CVE-2024-2881 Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remo… Wolfssl Mitigation only Fix from $1,9502024-08-30 HIGH 8.8 CVE-2024-1545 Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote … Wolfssl Patch available Fix from $1,9502024-08-29 MEDIUM 5.5 CVE-2024-1543 The side-channel protected T-Table implementation in wolfSSL up to version 5.6.5 protects against a side-channel attacker with cache-line resolution.… Wolfssl 5.6.6+ Fix from $1,6002024-08-29 HIGH 7.5 CVE-2024-5991 In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the fu… Wolfssl after 5.7.0 Fix from $1,9502024-08-27 MEDIUM 5.9 CVE-2024-5288 An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_C… Wolfssl 5.7.2+ Fix from $1,6002024-08-27 MEDIUM 5.3 CVE-2024-5814 A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful … Wolfssl after 5.7.0 Fix from $1,6002024-08-27 CRITICAL 9.1 CVE-2024-0901 Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause an out of bounds read via sending a malformed packet w… Wolfssl after 5.6.6 Fix from $2,3002024-03-25 CRITICAL 9.1 CVE-2023-6936 In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can tr… Wolfssl 5.6.6+ Fix from $2,3002024-02-20 MEDIUM 5.3 CVE-2023-6937 wolfSSL prior to 5.6.6 did not check that messages in one (D)TLS record do not span key boundaries. As a result, it was possible to combine (D)TLS me… Wolfssl 5.6.6+ Fix from $1,6002024-02-15 MEDIUM 5.9 CVE-2023-6935 wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a timing Bleichenbacher style attack, when built with the… Wolfssl after 5.6.4 Fix from $1,6002024-02-09 HIGH 8.8 CVE-2023-3724 If a TLS 1.3 client gets neither a PSK (pre shared key) extension nor a KSE (key share extension) when connecting to a malicious server, a default pr… Wolfssl 5.6.2+ Fix from $1,9502023-07-17 CRITICAL 9.1 CVE-2022-42905 In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can … Wolfssl 5.5.2+ Fix from $2,3002022-11-07 MEDIUM 5.3 CVE-2022-42961 An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signin… Wolfssl 5.5.0+ Fix from $1,6002022-10-15 HIGH 7.5 CVE-2022-39173 In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handshake. This occurs when an attacker supposedly resumes a … Wolfssl 5.5.1+ Fix from $1,9502022-09-29 MEDIUM 5.9 CVE-2021-44718 wolfSSL through 5.0.0 allows an attacker to cause a denial of service and infinite loop in the client component by sending crafted traffic from a Mac… Wolfssl after 5.0.0 Fix from $1,6002022-09-02 MEDIUM 5.9 CVE-2022-38153 An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however, only version 5.3.0 is exploitable. Man-in-the-middle… Wolfssl Patch available Fix from $1,6002022-08-31 HIGH 7.5 CVE-2022-38152 An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL server and SSL_clear is called on its session, the serve… Wolfssl 5.5.0+ Fix from $1,9502022-08-31 HIGH 7.5 CVE-2022-34293 wolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DTLS because a check for return-routability can be skipped. Wolfssl 5.4.0+ Fix from $1,9502022-08-08 HIGH 7.5 CVE-2022-25640 In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual authentication. A client can simply omit the certificate_v… Wolfssl 5.2.0+ Fix from $1,9502022-02-24 MEDIUM 6.5 CVE-2022-25638 In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication by a TLS 1.3 client to a TLS 1.3 server. This occurs … Wolfssl 5.2.0+ Fix from $1,6002022-02-24