OpenSSL

OpenSSL

326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.58%
  • Veröffentlicht 28.03.2023 15:15:06
  • Zuletzt bearbeitet 18.02.2025 21:15:13

Applications that use a non-default option when verifying certificates may be vulnerable to an attack from a malicious CA to circumvent certain checks. Invalid certificate policies in leaf certificates are silently ignored by OpenSSL and other certi...

  • EPSS 1.63%
  • Veröffentlicht 28.03.2023 15:15:06
  • Zuletzt bearbeitet 19.02.2025 18:15:22

The function X509_VERIFY_PARAM_add0_policy() is documented to implicitly enable the certificate policy check when doing certificate verification. However the implementation of the function does not enable the check which allows certificates with inva...

  • EPSS 3.66%
  • Veröffentlicht 22.03.2023 17:15:13
  • Zuletzt bearbeitet 05.05.2025 16:15:26

A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious c...

  • EPSS 1.4%
  • Veröffentlicht 24.02.2023 15:15:11
  • Zuletzt bearbeitet 04.11.2025 20:16:14

A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate...

  • EPSS 4.49%
  • Veröffentlicht 08.02.2023 20:15:24
  • Zuletzt bearbeitet 04.11.2025 20:16:15

The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user appl...

  • EPSS 1.85%
  • Veröffentlicht 08.02.2023 20:15:24
  • Zuletzt bearbeitet 04.11.2025 20:16:16

An invalid pointer dereference on read can be triggered when an application tries to load malformed PKCS7 data with the d2i_PKCS7(), d2i_PKCS7_bio() or d2i_PKCS7_fp() functions. The result of the dereference is an application crash which could lead ...

  • EPSS 1.85%
  • Veröffentlicht 08.02.2023 20:15:24
  • Zuletzt bearbeitet 04.11.2025 20:16:16

An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public k...

  • EPSS 59.5%
  • Veröffentlicht 08.02.2023 20:15:24
  • Zuletzt bearbeitet 04.11.2025 20:16:16

There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Add...

  • EPSS 1.85%
  • Veröffentlicht 08.02.2023 20:15:24
  • Zuletzt bearbeitet 04.11.2025 20:16:16

A NULL pointer can be dereferenced when signatures are being verified on PKCS7 signed or signedAndEnveloped data. In case the hash algorithm used for the signature is known to the OpenSSL library but the implementation of the hash algorithm is not av...

  • EPSS 16.2%
  • Veröffentlicht 08.02.2023 20:15:23
  • Zuletzt bearbeitet 04.11.2025 20:16:14

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able t...