Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2019-15651
wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/src/asn.c because reading the ASN_BOOLEAN byte is misha…
Wolfssl
Mitigation only
CRITICAL 9.8
CVE-2019-11873EPSS 9%
wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size is greater than a client identity size. An attacker se…
Wolfssl
Patch available
CRITICAL 9.8
CVE-2019-6439
examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.
Wolfssl
after 3.15.7
MEDIUM 5.9
CVE-2018-16870
It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This ma…
Wolfssl
3.15.7+
MEDIUM 5.9
CVE-2017-13099EPSS 25%
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can…
Wolfssl
3.12.2 / 6.5.4.6+
MEDIUM 5.9
CVE-2014-2903
CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate n…
Wolfssl
after 2.9.4
CRITICAL 9.8
CVE-2017-2800EPSS 9%
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certificate val…
Wolfssl
after 3.10.2
HIGH 7.8
CVE-2017-8854
wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, aka a buffer overflow triggered by a malformed temporary…
Wolfssl
after 3.10.0a
HIGH 7.5
CVE-2017-8855
wolfSSL before 3.11.0 does not prevent wc_DhAgree from accepting a malformed DH key.
Wolfssl
after 3.10.4
MEDIUM 5.5
CVE-2017-6076
In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to …
Wolfssl
3.10.2+
MEDIUM 5.5
CVE-2016-7439
The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging ca…
Wolfssl
after 3.9.8
MEDIUM 5.5
CVE-2016-7438
The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging ca…
Wolfssl
after 3.9.8
HIGH 7.5
CVE-2015-6925
wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a cra…
Wolfssl
after 3.6.6