Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-39908
The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may…
Yubihsm 2 Sdk
2023.08+
MEDIUM 6.5
CVE-2022-24584
Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP suppo…
Otp
No fix yet
HIGH 8.8
CVE-2015-3298
Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the …
Ykneo Openpgp
1.0.10+
HIGH 7.5
CVE-2021-43399
The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations includin…
Yubihsm 2 Software Development Kit
after 2021.08
MEDIUM 5.3
CVE-2020-15001
An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set option…
Yubikey 5 Nfc Firmware
after 5.3.1
MEDIUM 5.9
CVE-2020-15000
A PIN management problem was discovered on Yubico YubiKey 5 devices 5.2.0 to 5.2.6. OpenPGP has three passwords: Admin PIN, Reset Code, and User PIN.…
Yubikey 5 Nfc Firmware
after 5.2.6
HIGH 8.6
CVE-2020-10185
The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to pers…
Yubikey One Time Password Validation Server
2.40+
HIGH 7.5
CVE-2020-10184
The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denia…
Yubikey One Time Password Validation Server
2.40+
HIGH 8.1
CVE-2019-12210
In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a ne…
Pam U2f
Patch available
HIGH 7.5
CVE-2019-12209
Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and…
Pam U2f
Patch available
HIGH 7.5
CVE-2019-9578
In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.
Libu2f Host
1.1.8+
MEDIUM 6.8
CVE-2018-14779
A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function `yk…
Piv Manager
1.4.2 / 1.6.0+
HIGH 8.2
CVE-2018-9275
In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth ma…
Yubico Pam
after 2.25