Polarssl

Polarssl

15 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.43%
  • Published 27.10.2021 01:15:07
  • Last modified 21.11.2024 01:32:34

PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtua...

  • EPSS 0.07%
  • Published 06.12.2019 18:15:10
  • Last modified 21.11.2024 01:38:33

A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.

  • EPSS 0.92%
  • Published 02.11.2015 19:59:16
  • Last modified 12.04.2025 10:46:40

Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the se...

  • EPSS 1.7%
  • Published 02.11.2015 19:59:05
  • Last modified 12.04.2025 10:46:40

Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a lon...

  • EPSS 0.49%
  • Published 24.08.2015 15:59:03
  • Last modified 12.04.2025 10:46:40

Memory leak in PolarSSL before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of ClientHello messages. NOTE: this identifier was SPLIT from CVE-2014-8628 per ADT3 due to different affected versions...

  • EPSS 0.48%
  • Published 24.08.2015 15:59:00
  • Last modified 12.04.2025 10:46:40

Memory leak in PolarSSL before 1.2.12 and 1.3.x before 1.3.9 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted X.509 certificates. NOTE: this identifier has been SPLIT per ADT3 due to different a...

  • EPSS 4.46%
  • Published 27.01.2015 20:59:14
  • Last modified 12.04.2025 10:46:40

The asn1_get_sequence_of function in library/asn1parse.c in PolarSSL 1.0 through 1.2.12 and 1.3.x through 1.3.9 does not properly initialize a pointer in the asn1_sequence linked list, which allows remote attackers to cause a denial of service (crash...

  • EPSS 0.27%
  • Published 24.11.2014 15:59:11
  • Last modified 12.04.2025 10:46:40

PolarSSL 1.3.8 does not properly negotiate the signature algorithm to use, which allows remote attackers to conduct downgrade attacks via unspecified vectors.

  • EPSS 0.54%
  • Published 22.07.2014 14:55:09
  • Last modified 12.04.2025 10:46:40

The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensi...

  • EPSS 2.85%
  • Published 26.10.2013 17:55:03
  • Last modified 11.04.2025 00:51:21

Buffer overflow in the ssl_read_record function in ssl_tls.c in PolarSSL before 1.1.8, when using TLS 1.1, might allow remote attackers to execute arbitrary code via a long packet.