CVE-2025-34468
- EPSS 0.31%
- Veröffentlicht 31.12.2025 18:39:07
- Zuletzt bearbeitet 14.01.2026 20:18:32
libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address resolution when attacker-controlled hostname data is copied into a fixed 256-byte stack buffer without proper bounds checking. A rem...
CVE-2025-59391
- EPSS 0.05%
- Veröffentlicht 08.12.2025 17:16:20
- Zuletzt bearbeitet 12.12.2025 12:34:00
A memory disclosure vulnerability exists in libcoap's OSCORE configuration parser in libcoap before release-4.3.5-patches. An out-of-bounds read may occur when parsing certain configuration values, allowing an attacker to infer or read memory beyond ...
CVE-2025-65495
- EPSS 0.12%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 17:15:30
Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate that causes i2d_X509() to return -1 and be misused as a malloc() size pa...
CVE-2025-65501
- EPSS 0.14%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:18:11
Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSL_get_app_data() returns NULL.
CVE-2025-65500
- EPSS 0.14%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:28:13
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
CVE-2025-65499
- EPSS 0.14%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:29:53
Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_ex_data_X509_STORE_CTX_idx() to return -1.
CVE-2025-65498
- EPSS 0.14%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:31:43
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
CVE-2025-65497
- EPSS 0.14%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 16:55:53
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
CVE-2025-65496
- EPSS 0.14%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 17:00:40
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
CVE-2025-65494
- EPSS 0.12%
- Veröffentlicht 24.11.2025 00:00:00
- Zuletzt bearbeitet 01.12.2025 17:17:59
NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certificate that causes sk_GENERAL_NAME_value() to return NULL.