Vulnerabilities (CVE)

Filtered by vendor Openbsd Subscribe
Filtered by product Libressl
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-41581 1 Openbsd 1 Libressl 2021-09-29 4.3 MEDIUM 5.5 MEDIUM
x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buffer over-read. When the input exceeds DOMAIN_PART_MAX_LEN, the buffer lacks '\0' termination.
CVE-2017-8301 1 Openbsd 1 Libressl 2019-10-03 2.6 LOW 5.3 MEDIUM
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.
CVE-2018-12434 1 Openbsd 1 Libressl 2018-08-06 1.9 LOW 4.7 MEDIUM
LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.