CVE-2024-28960
- EPSS 0.84%
- Veröffentlicht 29.03.2024 06:15:07
- Zuletzt bearbeitet 05.06.2026 19:38:32
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
CVE-2024-23775
- EPSS 1.12%
- Veröffentlicht 31.01.2024 08:15:42
- Zuletzt bearbeitet 05.06.2026 19:38:32
Integer Overflow vulnerability in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2, allows attackers to cause a denial of service (DoS) via mbedtls_x509_set_extension().
CVE-2024-23170
- EPSS 0.31%
- Veröffentlicht 31.01.2024 08:15:42
- Zuletzt bearbeitet 05.06.2026 19:38:32
An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It requires the attacker to se...
CVE-2024-23744
- EPSS 0.69%
- Veröffentlicht 21.01.2024 23:15:44
- Zuletzt bearbeitet 05.06.2026 19:38:32
An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.
CVE-2023-45199
- EPSS 1.05%
- Veröffentlicht 07.10.2023 01:15:10
- Zuletzt bearbeitet 05.06.2026 19:38:32
Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
CVE-2023-43615
- EPSS 0.78%
- Veröffentlicht 07.10.2023 01:15:10
- Zuletzt bearbeitet 05.06.2026 19:38:32
Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
CVE-2021-36647
- EPSS 0.16%
- Veröffentlicht 17.01.2023 21:15:10
- Zuletzt bearbeitet 05.06.2026 19:38:32
Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory access information (...
CVE-2022-46393
- EPSS 1.15%
- Veröffentlicht 15.12.2022 23:15:10
- Zuletzt bearbeitet 05.06.2026 19:38:32
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_...
CVE-2022-46392
- EPSS 0.79%
- Veröffentlicht 15.12.2022 23:15:10
- Zuletzt bearbeitet 05.06.2026 19:38:32
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key ...
CVE-2022-35409
- EPSS 1.83%
- Veröffentlicht 15.07.2022 14:15:09
- Zuletzt bearbeitet 05.06.2026 19:38:32
An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This ca...