Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
matrixssl matrixssl vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-43974
MatrixSSL 4.0.4 up to and including 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a crafted TLS Message to cause a buffer overflow and achieve remote code execution. This is fixed in 4.6.0.
Matrixssl Matrixssl
5.9
CVSSv3
CVE-2016-6882
MatrixSSL prior to 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote malicious users to obtain RSA private key information by conducting a Lenstra side-channel attack.
Matrixssl Matrixssl
6.5
CVSSv3
CVE-2016-6884
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL prior to 3.8.3 allow remote malicious users to cause a denial of service (out-of-bounds read) via a crafted message.
Matrixssl Matrixssl
7.5
CVSSv3
CVE-2016-6885
The pstm_exptmod function in MatrixSSL prior to 3.8.4 allows remote malicious users to cause a denial of service (invalid free and crash) via a base zero value for the modular exponentiation.
Matrixssl Matrixssl
7.5
CVSSv3
CVE-2016-6886
The pstm_reverse function in MatrixSSL prior to 3.8.4 allows remote malicious users to cause a denial of service (invalid memory read and crash) via a (1) zero value or (2) the key's modulus for the secret key during RSA key exchange.
Matrixssl Matrixssl
9.8
CVSSv3
CVE-2016-6890
Heap-based buffer overflow in MatrixSSL prior to 3.8.6 allows remote malicious users to execute arbitrary code via a crafted Subject Alt Name in an X.509 certificate.
Matrixssl Matrixssl
7.5
CVSSv3
CVE-2016-6891
MatrixSSL prior to 3.8.6 allows remote malicious users to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in an X.509 certificate.
Matrixssl Matrixssl
7.5
CVSSv3
CVE-2016-6892
The x509FreeExtensions function in MatrixSSL prior to 3.8.6 allows remote malicious users to cause a denial of service (free of unallocated memory) via a crafted X.509 certificate.
Matrixssl Matrixssl
5.9
CVSSv3
CVE-2016-8671
The pstm_exptmod function in MatrixSSL 3.8.6 and previous versions does not properly perform modular exponentiation, which might allow remote malicious users to predict the secret key via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-20...
Matrixssl Matrixssl
7.5
CVSSv3
CVE-2019-16747
In MatrixSSL prior to 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerability than CVE-2019-14431.
Matrixssl Matrixssl
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »