CVE-2021-45451
- EPSS 0.12%
- Veröffentlicht 21.12.2021 07:15:06
- Zuletzt bearbeitet 21.11.2024 06:32:14
In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
CVE-2021-45450
- EPSS 0.07%
- Veröffentlicht 21.12.2021 07:15:06
- Zuletzt bearbeitet 21.11.2024 06:32:14
In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
CVE-2021-44732
- EPSS 0.93%
- Veröffentlicht 20.12.2021 08:15:06
- Zuletzt bearbeitet 03.11.2025 20:15:51
Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
CVE-2020-36478
- EPSS 0.29%
- Veröffentlicht 23.08.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 05:29:38
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). A NULL algorithm parameters entry looks identical to an array of REAL (size zero) and thus the certificate is considered valid. However, if the parameter...
CVE-2020-36477
- EPSS 0.22%
- Veröffentlicht 23.08.2021 02:15:07
- Zuletzt bearbeitet 21.11.2024 05:29:38
An issue was discovered in Mbed TLS before 2.24.0. The verification of X.509 certificates when matching the expected common name (the cn argument of mbedtls_x509_crt_verify) with the actual certificate name is mishandled: when the subjecAltName exten...
CVE-2020-36476
- EPSS 0.25%
- Veröffentlicht 23.08.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 05:29:37
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.
CVE-2020-36475
- EPSS 0.41%
- Veröffentlicht 23.08.2021 02:15:06
- Zuletzt bearbeitet 21.11.2024 05:29:37
An issue was discovered in Mbed TLS before 2.25.0 (and before 2.16.9 LTS and before 2.7.18 LTS). The calculations performed by mbedtls_mpi_exp_mod are not limited; thus, supplying overly large parameters could lead to denial of service when generatin...
CVE-2020-36426
- EPSS 0.23%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).
CVE-2020-36425
- EPSS 0.3%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
CVE-2020-36424
- EPSS 0.09%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.