OpenSSL

OpenSSL

274 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.02%
  • Veröffentlicht 27.01.2026 16:16:35
  • Zuletzt bearbeitet 02.02.2026 18:41:14

Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on mem...

Medienbericht
  • EPSS 0.07%
  • Veröffentlicht 27.01.2026 16:16:35
  • Zuletzt bearbeitet 02.02.2026 18:40:27

Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing mal...

Medienbericht
  • EPSS 0.06%
  • Veröffentlicht 27.01.2026 16:16:34
  • Zuletzt bearbeitet 02.02.2026 18:35:02

Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: T...

Medienbericht
  • EPSS 0.07%
  • Veröffentlicht 27.01.2026 16:16:34
  • Zuletzt bearbeitet 02.02.2026 18:33:30

Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed...

Medienbericht
  • EPSS 0.06%
  • Veröffentlicht 27.01.2026 16:16:34
  • Zuletzt bearbeitet 02.02.2026 18:29:59

Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an applicatio...

Medienbericht
  • EPSS 0.01%
  • Veröffentlicht 27.01.2026 16:16:33
  • Zuletzt bearbeitet 02.02.2026 18:36:03

Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact su...

Medienbericht
  • EPSS 0.06%
  • Veröffentlicht 27.01.2026 16:16:15
  • Zuletzt bearbeitet 02.02.2026 18:37:19

Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit. Impact summary: An attacker can cause per-connection memo...

Medienbericht
  • EPSS 0.01%
  • Veröffentlicht 27.01.2026 16:16:15
  • Zuletzt bearbeitet 02.02.2026 18:36:57

Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary: This out-of-bounds write can cause memory corrupt...

Medienbericht
  • EPSS 0.01%
  • Veröffentlicht 27.01.2026 16:16:14
  • Zuletzt bearbeitet 02.02.2026 18:39:21

Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer ...

Medienbericht
  • EPSS 0.66%
  • Veröffentlicht 27.01.2026 16:16:14
  • Zuletzt bearbeitet 02.02.2026 18:38:55

Issue summary: Parsing CMS AuthEnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code exe...