Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gnutls vulnerabilities and exploits
(subscribe to this query)
5.5
CVSSv3
CVE-2022-1615
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
Samba Samba
Fedoraproject Fedora 37
5.3
CVSSv3
CVE-2022-1328
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 prior to 2.2.3 allows read past end of input line
Mutt Mutt
Debian Debian Linux 9.0
Fedoraproject Fedora 36
5.3
CVSSv3
CVE-2020-28896
Mutt prior to 2.0.2 and NeoMutt prior to 2020-11-20 did not ensure that $ssl_force_tls was processed if an IMAP server's initial server response was invalid. The connection was not properly closed, and the code could continue attempting to authenticate. This could result in ...
Mutt Mutt
Neomutt Neomutt
Debian Debian Linux 9.0
4.8
CVSSv3
CVE-2022-28352
WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 prior to 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which allows man-in-the-middle malicious users to spoof a TLS chat server via an arbitrary certificate. ...
Weechat Weechat
4.8
CVSSv3
CVE-2020-14154
Mutt prior to 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate.
Mutt Mutt
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 19.10
Canonical Ubuntu Linux 20.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 12.04
NA
CVE-2024-28834
A flaw was found in GnuTLS. The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noti...
NA
CVE-2024-28835
A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command.
NA
CVE-2015-3308
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS prior to 3.3.14 allows remote malicious users to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
Gnu Gnutls
Canonical Ubuntu Linux 15.04
NA
CVE-2015-6251
Double free vulnerability in GnuTLS prior to 3.3.17 and 3.4.x prior to 3.4.4 allows remote malicious users to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
Gnu Gnutls 3.3.16
Gnu Gnutls 3.3.15
Gnu Gnutls 3.3.8
Gnu Gnutls 3.3.7
Gnu Gnutls 3.3.0
Gnu Gnutls 3.3.12
Gnu Gnutls 3.3.11
Gnu Gnutls 3.3.4
Gnu Gnutls 3.3.3
Gnu Gnutls 3.4.3
Gnu Gnutls 3.3.10
Gnu Gnutls 3.3.9
Gnu Gnutls 3.3.2
Gnu Gnutls 3.3.1
Gnu Gnutls 3.3.14
Gnu Gnutls 3.3.13
Gnu Gnutls 3.3.6
Gnu Gnutls 3.3.5
Gnu Gnutls 3.4.0
Gnu Gnutls 3.4.1
Gnu Gnutls 3.4.2
Debian Debian Linux 8.0
NA
CVE-2014-8155
GnuTLS prior to 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle malicious users to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.
Gnu Gnutls
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »