Erlang

Otp

61 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 27.07.2026 16:17:41
  • Zuletzt bearbeitet 10.08.2026 20:25:42

Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation. This vulnerability is associated with program files erts/emulator/beam/...

  • EPSS 0.73%
  • Veröffentlicht 27.07.2026 15:25:03
  • Zuletzt bearbeitet 08.09.2026 01:17:51

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encod...

  • EPSS 0.21%
  • Veröffentlicht 27.07.2026 15:21:29
  • Zuletzt bearbeitet 08.09.2026 01:17:50

The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates th...

  • EPSS 0.29%
  • Veröffentlicht 27.07.2026 15:13:54
  • Zuletzt bearbeitet 10.08.2026 20:24:25

Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtu...

  • EPSS 0.15%
  • Veröffentlicht 27.07.2026 15:03:50
  • Zuletzt bearbeitet 24.09.2026 21:17:12

Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 and zip:extract/1,2 validate entry paths using zip:check_dir_level/2, whi...

  • EPSS 0.44%
  • Veröffentlicht 27.07.2026 14:58:24
  • Zuletzt bearbeitet 10.08.2026 20:26:36

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion. The do_accept function in ert...

  • EPSS 0.37%
  • Veröffentlicht 27.07.2026 14:39:44
  • Zuletzt bearbeitet 10.08.2026 15:50:11

The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl_certificate:handle_incomplete_chain/5, the received chain is passed to ssl_certificate:build_certifi...

  • EPSS 0.14%
  • Veröffentlicht 02.07.2026 16:06:30
  • Zuletzt bearbeitet 08.09.2026 01:17:31

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl (tls_gen_connection module) allows a network-positioned attacker to inject unauthenticated plaintext that the TLS client applicat...

  • EPSS 0.38%
  • Veröffentlicht 02.07.2026 16:06:24
  • Zuletzt bearbeitet 24.07.2026 15:18:32

Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener. A DTLS server listener uses a single shared dtls_...

  • EPSS 0.33%
  • Veröffentlicht 02.07.2026 16:06:20
  • Zuletzt bearbeitet 24.07.2026 15:18:03

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render an SFTP channel permanently unresponsive. The handle_data/4 function in ssh_sftpd contains a catch-...