CVE-2023-52892
- EPSS 0.14%
- Veröffentlicht 27.06.2024 22:15:10
- Zuletzt bearbeitet 21.11.2024 08:40:48
In phpseclib before 1.0.22, 2.x before 2.0.46, and 3.x before 3.0.33, some characters in Subject Alternative Name fields in TLS certificates are incorrectly allowed to have a special meaning in regular expressions (such as a + wildcard), leading to n...
CVE-2024-27354
- EPSS 0.13%
- Veröffentlicht 01.03.2024 23:15:08
- Zuletzt bearbeitet 15.09.2025 17:58:58
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. An attacker can construct a malformed certificate containing an extremely large prime to cause a denial of service (CPU consumption for an isPrime prima...
CVE-2024-27355
- EPSS 0.13%
- Veröffentlicht 01.03.2024 23:15:08
- Zuletzt bearbeitet 15.09.2025 17:17:49
An issue was discovered in phpseclib 1.x before 1.0.23, 2.x before 2.0.47, and 3.x before 3.0.36. When processing the ASN.1 object identifier of a certificate, a sub identifier may be provided that leads to a denial of service (CPU consumption for de...
CVE-2023-49316
- EPSS 0.11%
- Veröffentlicht 27.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:33:13
In Math/BinaryField.php in phpseclib 3 before 3.0.34, excessively large degrees can lead to a denial of service.
CVE-2023-27560
- EPSS 0.18%
- Veröffentlicht 03.03.2023 06:15:08
- Zuletzt bearbeitet 06.03.2025 21:15:13
Math/PrimeField.php in phpseclib 3.x before 3.0.19 has an infinite loop with composite primefields.
CVE-2021-30130
- EPSS 0.2%
- Veröffentlicht 06.04.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 06:03:22
phpseclib before 2.0.31 and 3.x before 3.0.7 mishandles RSA PKCS#1 v1.5 signature verification.