CVE-2025-11187
- EPSS 4.52%
- Veröffentlicht 27.01.2026 16:16:14
- Zuletzt bearbeitet 20.03.2026 14:16:13
Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. Impact summary: The stack buffer overflow or NULL pointer ...
CVE-2025-15467
- EPSS 47.62%
- Veröffentlicht 27.01.2026 16:16:14
- Zuletzt bearbeitet 07.09.2026 13:17:27
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentiall...
CVE-2025-15468
- EPSS 0.75%
- Veröffentlicht 27.01.2026 16:16:14
- Zuletzt bearbeitet 02.02.2026 18:38:00
Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs. Impact summary: A NULL pointer dereference leads to abnormal termina...
CVE-2025-15469
- EPSS 0.18%
- Veröffentlicht 27.01.2026 16:16:14
- Zuletzt bearbeitet 02.02.2026 18:37:39
Issue summary: The 'openssl dgst' command-line tool silently truncates input data to 16MB when using one-shot signing algorithms and reports success instead of an error. Impact summary: A user signing or verifying files larger than 16MB with one-sho...
CVE-2025-9230
- EPSS 1.55%
- Veröffentlicht 30.09.2025 14:15:41
- Zuletzt bearbeitet 14.07.2026 13:18:07
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an a...
CVE-2025-9231
- EPSS 2.23%
- Veröffentlicht 30.09.2025 14:15:41
- Zuletzt bearbeitet 14.07.2026 13:18:07
Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit A...
CVE-2025-9232
- EPSS 1.99%
- Veröffentlicht 30.09.2025 14:15:41
- Zuletzt bearbeitet 14.07.2026 13:18:07
Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summ...
CVE-2025-45765
- EPSS 0.16%
- Veröffentlicht 07.08.2025 21:15:27
- Zuletzt bearbeitet 15.04.2026 00:35:42
ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not something that is enforced by this library. Currently more recent versions of OpenSSL are enforcing some key sizes and those restrict...
CVE-2025-27587
- EPSS 0.38%
- Veröffentlicht 16.06.2025 00:00:00
- Zuletzt bearbeitet 15.04.2026 00:35:42
OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) fro...
CVE-2025-4575
- EPSS 0.34%
- Veröffentlicht 22.05.2025 13:36:49
- Zuletzt bearbeitet 23.10.2025 14:51:30
Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instea...