CVE-2011-4574
- EPSS 0.43%
- Veröffentlicht 27.10.2021 01:15:07
- Zuletzt bearbeitet 21.11.2024 01:32:34
PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtua...
CVE-2012-2130
- EPSS 0.07%
- Veröffentlicht 06.12.2019 18:15:10
- Zuletzt bearbeitet 21.11.2024 01:38:33
A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
CVE-2015-8036
- EPSS 0.92%
- Veröffentlicht 02.11.2015 19:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the se...
CVE-2015-5291
- EPSS 1.7%
- Veröffentlicht 02.11.2015 19:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a lon...
CVE-2014-9744
- EPSS 0.49%
- Veröffentlicht 24.08.2015 15:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of ClientHello messages. NOTE: this identifier was SPLIT from CVE-2014-8628 per ADT3 due to different affected versions...
CVE-2014-8628
- EPSS 0.48%
- Veröffentlicht 24.08.2015 15:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted X.509 certificates. NOTE: this identifier has been SPLIT per ADT3 due to different a...
CVE-2015-1182
- EPSS 4.46%
- Veröffentlicht 27.01.2015 20:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointer in the asn1_sequence linked list, which allows remote attackers to cause a denial of service (crash...
- EPSS 0.27%
- Veröffentlicht 24.11.2014 15:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
PolarSSL 1.3.8 does not properly negotiate the signature algorithm to use, which allows remote attackers to conduct downgrade attacks via unspecified vectors.
- EPSS 0.54%
- Veröffentlicht 22.07.2014 14:55:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensi...
CVE-2013-5914
- EPSS 2.85%
- Veröffentlicht 26.10.2013 17:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the ssl_read_record function in ssl_tls.c in PolarSSL before 1.1.8, when using TLS 1.1, might allow remote attackers to execute arbitrary code via a long packet.