CVE-2026-28388
- EPSS 0.89%
- Veröffentlicht 07.04.2026 22:16:20
- Zuletzt bearbeitet 24.07.2026 23:10:00
Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A NULL pointer dereference can trigger a crash which ...
CVE-2026-2673
- EPSS 0.44%
- Veröffentlicht 13.03.2026 13:23:00
- Zuletzt bearbeitet 05.06.2026 19:48:51
Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may...
CVE-2026-22795
- EPSS 0.14%
- Veröffentlicht 27.01.2026 16:16:35
- Zuletzt bearbeitet 12.05.2026 13:17:32
Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on mem...
CVE-2026-22796
- EPSS 0.5%
- Veröffentlicht 27.01.2026 16:16:35
- Zuletzt bearbeitet 12.05.2026 13:17:32
Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing mal...
CVE-2025-69419
- EPSS 0.44%
- Veröffentlicht 27.01.2026 16:16:34
- Zuletzt bearbeitet 12.05.2026 13:17:26
Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: T...
CVE-2025-69420
- EPSS 0.77%
- Veröffentlicht 27.01.2026 16:16:34
- Zuletzt bearbeitet 12.05.2026 13:17:26
Issue summary: A type confusion vulnerability exists in the TimeStamp Response verification code where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing a malformed...
CVE-2025-69421
- EPSS 0.84%
- Veröffentlicht 27.01.2026 16:16:34
- Zuletzt bearbeitet 12.05.2026 13:17:26
Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an applicatio...
- EPSS 0.12%
- Veröffentlicht 27.01.2026 16:16:33
- Zuletzt bearbeitet 12.05.2026 13:17:24
Issue summary: When using the low-level OCB API directly with AES-NI or<br>other hardware-accelerated code paths, inputs whose length is not a multiple<br>of 16 bytes can leave the final partial block unencrypted and unauthenticated.<br><br>Impact su...
CVE-2025-66199
- EPSS 0.4%
- Veröffentlicht 27.01.2026 16:16:15
- Zuletzt bearbeitet 02.02.2026 18:37:19
Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit. Impact summary: An attacker can cause per-connection memo...
CVE-2025-68160
- EPSS 0.15%
- Veröffentlicht 27.01.2026 16:16:15
- Zuletzt bearbeitet 12.05.2026 13:17:24
Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary: This out-of-bounds write can cause memory corrupt...