Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Matrixssl HIGH 7.5
CVE-2023-24609

Matrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in t…

Fix: after 4.6.0
Fix from $1,950 2023-12-22
Matrixssl HIGH 7.5
CVE-2022-46505

An issue in MatrixSSL 4.5.1-open and earlier leads to failure to securely check the SessionID field, resulting in the misuse of an all-zero MasterSec…

Fix: after 4.5.1
Fix from $1,950 2023-01-18
Matrixssl CRITICAL 9.8
CVE-2022-43974

MatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a crafted TLS Message to cause…

Fix: 4.6.0+
Fix from $2,300 2023-01-09
Matrixssl HIGH 7.5
CVE-2019-16747

In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted…

Fix: 4.2.2+
Fix from $1,950 2020-12-30
Matrixssl MEDIUM 5.9
CVE-2019-13629

MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or a remote attacker, able to measure t…

Fix: after 4.2.1
Fix from $1,600 2019-10-03
Matrixssl CRITICAL 9.8
CVE-2019-14431

In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256…

Fix: after 4.2.1
Fix from $2,300 2019-07-29
Matrixssl CRITICAL 9.8
CVE-2019-13470

MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.

Fix: 4.2.1+
Fix from $2,300 2019-07-09
Matrixssl CRITICAL 9.8
CVE-2019-10914

pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 certifica…

Fix: after 4.0.2
Fix from $2,300 2019-04-08
Matrixssl MEDIUM 5.3
CVE-2017-1000417

MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509…

Mitigation only
Fix from $1,600 2018-01-22
Matrixssl MEDIUM 5.9
CVE-2017-1000415

MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates hav…

Mitigation only
Fix from $1,600 2018-01-09
Matrixssl CRITICAL 9.8
CVE-2017-2780

An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially …

No fix yet
Fix from $2,300 2017-06-22
Matrixssl CRITICAL 9.8
CVE-2017-2781

An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially …

No fix yet
Fix from $2,300 2017-06-22
Matrixssl CRITICAL 9.1
CVE-2017-2782

An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 cer…

No fix yet
Fix from $2,300 2017-06-22
Matrixssl MEDIUM 6.5
CVE-2016-6884

TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read)…

Fix: after 3.8.2
Fix from $1,600 2017-03-03
Matrixssl MEDIUM 5.9
CVE-2016-6882

MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information …

Fix: after 3.8.6
Fix from $1,600 2017-03-03
Matrixssl MEDIUM 5.9
CVE-2016-6883EPSS 14%

MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack.

Fix: after 3.8.2
Fix from $1,600 2017-03-03
Matrixssl HIGH 7.5
CVE-2016-6885

The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base zero val…

Fix: after 3.8.3
Fix from $1,950 2017-01-13
Matrixssl HIGH 7.5
CVE-2016-6886

The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via a (1) ze…

Fix: after 3.8.3
Fix from $1,950 2017-01-13
Matrixssl MEDIUM 5.9
CVE-2016-6887

The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to pred…

Fix: after 3.8.6
Fix from $1,600 2017-01-13
Matrixssl MEDIUM 5.9
CVE-2016-8671

The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to pred…

Fix: after 3.8.6
Fix from $1,600 2017-01-13
Matrixssl CRITICAL 9.8
CVE-2016-6890EPSS 6%

Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an X.509 cer…

Fix: after 3.8.5
Fix from $2,300 2017-01-05
Matrixssl HIGH 7.5
CVE-2016-6891

MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in an X.509 …

Fix: after 3.8.5
Fix from $1,950 2017-01-05
Matrixssl HIGH 7.5
CVE-2016-6892

The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory) via a cra…

Fix: after 3.8.5
Fix from $1,950 2017-01-05