CVE-2020-36422
- EPSS 0.17%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.23.0. A side channel allows recovery of an ECC private key, related to mbedtls_ecp_check_pub_priv, mbedtls_pk_parse_key, mbedtls_pk_parse_keyfile, mbedtls_ecp_mul, and mbedtls_ecp_mul_restartable.
CVE-2020-36423
- EPSS 0.2%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.23.0. A remote attacker can recover plaintext because a certain Lucky 13 countermeasure doesn't properly consider the case of a hardware accelerator.
CVE-2020-36424
- EPSS 0.09%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.24.0. An attacker can recover a private key (for RSA or static Diffie-Hellman) via a side-channel attack against generation of base blinding/unblinding values.
CVE-2020-36425
- EPSS 0.3%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.24.0. It incorrectly uses a revocationDate check when deciding whether to honor certificate revocation via a CRL. In some situations, an attacker can exploit this by changing the local clock.
CVE-2020-36426
- EPSS 0.23%
- Veröffentlicht 19.07.2021 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:29:28
An issue was discovered in Arm Mbed TLS before 2.24.0. mbedtls_x509_crl_parse_der has a buffer over-read (of one byte).
CVE-2021-36773
- EPSS 1.51%
- Veröffentlicht 18.07.2021 04:15:08
- Zuletzt bearbeitet 21.11.2024 06:14:04
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss ...
CVE-2021-32743
- EPSS 0.65%
- Veröffentlicht 15.07.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:39
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga...
CVE-2021-32739
- EPSS 0.66%
- Veröffentlicht 15.07.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:38
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege esca...
CVE-2021-36740
- EPSS 0.12%
- Veröffentlicht 14.07.2021 17:15:08
- Zuletzt bearbeitet 21.11.2024 06:13:59
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x be...
CVE-2021-24119
- EPSS 0.26%
- Veröffentlicht 14.07.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 05:52:23
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software runni...