Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-39908 The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may… Yubihsm 2 Sdk 2023.08+ Fix from $1,9502023-08-14 MEDIUM 6.5 CVE-2022-24584 Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP suppo… Otp No fix yet Fix from $1,6002022-05-11 HIGH 8.8 CVE-2015-3298 Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the … Ykneo Openpgp 1.0.10+ Fix from $1,9502022-03-30 HIGH 7.5 CVE-2021-43399 The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations includin… Yubihsm 2 Software Development Kit after 2021.08 Fix from $1,9502021-12-08 MEDIUM 5.3 CVE-2020-15001 An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set option… Yubikey 5 Nfc Firmware after 5.3.1 Fix from $1,6002020-07-09 MEDIUM 5.9 CVE-2020-15000 A PIN management problem was discovered on Yubico YubiKey 5 devices 5.2.0 to 5.2.6. OpenPGP has three passwords: Admin PIN, Reset Code, and User PIN.… Yubikey 5 Nfc Firmware after 5.2.6 Fix from $1,6002020-07-09 HIGH 8.6 CVE-2020-10185 The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to pers… Yubikey One Time Password Validation Server 2.40+ Fix from $1,9502020-03-05 HIGH 7.5 CVE-2020-10184 The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denia… Yubikey One Time Password Validation Server 2.40+ Fix from $1,9502020-03-05 HIGH 8.1 CVE-2019-12210 In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a ne… Pam U2f Patch available Fix from $1,9502019-06-04 HIGH 7.5 CVE-2019-12209 Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and… Pam U2f Patch available Fix from $1,9502019-06-04 HIGH 7.5 CVE-2019-9578 In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device. Libu2f Host 1.1.8+ Fix from $1,9502019-03-05 MEDIUM 6.8 CVE-2018-14779 A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function `yk… Piv Manager 1.4.2 / 1.6.0+ Fix from $1,6002018-08-15 HIGH 8.2 CVE-2018-9275 In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth ma… Yubico Pam after 2.25 Fix from $1,9502018-04-04