CVE-2017-1000415
- EPSS 0.11%
- Published 09.01.2018 20:29:00
- Last modified 21.11.2024 03:04:41
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.
CVE-2017-2782
- EPSS 0.24%
- Published 22.06.2017 21:29:00
- Last modified 20.04.2025 01:37:25
An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation...
CVE-2017-2781
- EPSS 4.58%
- Published 22.06.2017 21:29:00
- Last modified 20.04.2025 01:37:25
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. ...
CVE-2017-2780
- EPSS 5.52%
- Published 22.06.2017 21:29:00
- Last modified 20.04.2025 01:37:25
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. ...
CVE-2016-6884
- EPSS 0.48%
- Published 03.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.
CVE-2016-6883
- EPSS 69.77%
- Published 03.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack.
CVE-2016-6882
- EPSS 0.38%
- Published 03.03.2017 16:59:00
- Last modified 20.04.2025 01:37:25
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information by conducting a Lenstra side-channel attack.
CVE-2016-8671
- EPSS 0.37%
- Published 13.01.2017 16:59:00
- Last modified 20.04.2025 01:37:25
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via unspecified vectors. NOTE: this vulnerability exists because of an incomplete ...
CVE-2016-6887
- EPSS 0.3%
- Published 13.01.2017 16:59:00
- Last modified 20.04.2025 01:37:25
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via a CRT attack.
CVE-2016-6886
- EPSS 0.81%
- Published 13.01.2017 16:59:00
- Last modified 20.04.2025 01:37:25
The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via a (1) zero value or (2) the key's modulus for the secret key during RSA key exchange.