Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yubihsm 2 Sdk HIGH 7.5
CVE-2023-39908

The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may…

Fix: 2023.08+
Fix from $1,950 2023-08-14
Otp MEDIUM 6.5
CVE-2022-24584

Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP suppo…

No fix yet
Fix from $1,600 2022-05-11
Ykneo Openpgp HIGH 8.8
CVE-2015-3298

Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the …

Fix: 1.0.10+
Fix from $1,950 2022-03-30
Yubihsm 2 Software Development Kit HIGH 7.5
CVE-2021-43399

The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations includin…

Fix: after 2021.08
Fix from $1,950 2021-12-08
Yubikey 5 Nfc Firmware MEDIUM 5.3
CVE-2020-15001

An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set option…

Fix: after 5.3.1
Fix from $1,600 2020-07-09
Yubikey 5 Nfc Firmware MEDIUM 5.9
CVE-2020-15000

A PIN management problem was discovered on Yubico YubiKey 5 devices 5.2.0 to 5.2.6. OpenPGP has three passwords: Admin PIN, Reset Code, and User PIN.…

Fix: after 5.2.6
Fix from $1,600 2020-07-09
Yubikey One Time Password Validation Server HIGH 8.6
CVE-2020-10185

The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to pers…

Fix: 2.40+
Fix from $1,950 2020-03-05
Yubikey One Time Password Validation Server HIGH 7.5
CVE-2020-10184

The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denia…

Fix: 2.40+
Fix from $1,950 2020-03-05
Pam U2f HIGH 8.1
CVE-2019-12210

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a ne…

Patch available
Fix from $1,950 2019-06-04
Pam U2f HIGH 7.5
CVE-2019-12209

Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and…

Patch available
Fix from $1,950 2019-06-04
Libu2f Host HIGH 7.5
CVE-2019-9578

In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.

Fix: 1.1.8+
Fix from $1,950 2019-03-05
Piv Manager MEDIUM 6.8
CVE-2018-14779

A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function `yk…

Fix: 1.4.2 / 1.6.0+
Fix from $1,600 2018-08-15
Yubico Pam HIGH 8.2
CVE-2018-9275

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth ma…

Fix: after 2.25
Fix from $1,950 2018-04-04