All vulnerabilities
111 / 111
Sort
5.9
CVE-2017-13099DEB
wolfSSL prior to version 3.12.2 provides a weak Bleichenbacher oracle when any TLS cipher suite…
2017-01-01Pre-auth
EPSS24.9%
pct 97
9.8
CVE-2019-11873DEB
wolfSSL 4.0.0 has a Buffer Overflow in DoPreSharedKeys in tls13.c when a current identity size …
2019-01-01Pre-auth
EPSS8.8%
pct 94
9.8
CVE-2017-2800DEB
A specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL…
2017-01-01Pre-auth
EPSS8.5%
pct 94
5.9
CVE-2015-7744DEB
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chin…
2015-01-01Pre-auth
EPSS5.0%
pct 91
7.5
CVE-2022-39173DEB
In wolfSSL before 5.5.1, malicious clients can cause a buffer overflow during a TLS 1.3 handsha…
2022-01-01Pre-auth
EPSS4.3%
pct 89
9.8
CVE-2020-36177DEB
RsaPad_PSS in wolfcrypt/src/rsa.c in wolfSSL before 4.6.0 has an out-of-bounds write for certai…
2020-01-01Pre-auth
EPSS3.5%
pct 87
9.8
CVE-2014-2898DEB
wolfSSL CyaSSL before 2.9.4 allows remote attackers to have unspecified impact via multiple cal…
2014-01-01Pre-auth
EPSS2.8%
pct 84
9.8
CVE-2014-2897DEB
The SSL 3 HMAC functionality in wolfSSL CyaSSL 2.5.0 before 2.9.4 does not check the padding le…
2014-01-01Pre-auth
EPSS2.8%
pct 84
9.8
CVE-2014-2896DEB
The DoAlert function in the (1) TLS and (2) DTLS implementations in wolfSSL CyaSSL before 2.9.4…
2014-01-01Pre-auth
EPSS2.8%
pct 84
7.5
CVE-2015-6925DEB
wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (re…
2015-01-01Pre-auth
EPSS2.7%
pct 84
9.8
CVE-2019-6439DEB
examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based b…
2019-01-01Pre-auth
EPSS2.6%
pct 82
7.5
CVE-2022-38152DEB
An issue was discovered in wolfSSL before 5.5.0. When a TLS 1.3 client connects to a wolfSSL se…
2022-01-01Pre-auth
EPSS2.1%
pct 78
7.5
CVE-2019-18840DEB
In wolfSSL 4.1.0 through 4.2.0c, there are missing sanity checks of memory accesses in parsing …
2019-01-01Pre-auth
EPSS2.0%
pct 77
7.5
CVE-2020-11713DEB
wolfSSL 4.3.0 has mulmod code in wc_ecc_mulmod_ex in ecc.c that does not properly resist timing…
2020-01-01Pre-auth
EPSS2.0%
pct 77
9.1
CVE-2022-42905DEB
In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), th…
2022-01-01Pre-auth
EPSS2.0%
pct 77
7.8
CVE-2017-8854DEB
wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, ak…
2017-01-01
EPSS1.8%
pct 75
5.3
CVE-2019-14317DEB
wolfSSL and wolfCrypt 4.1.0 and earlier (formerly known as CyaSSL) generate biased DSA nonces. …
2019-01-01Pre-auth
EPSS1.8%
pct 74
5.9
CVE-2022-38153DEB
An issue was discovered in wolfSSL before 5.5.0 (when --enable-session-ticket is used); however…
2022-01-01Pre-auth
EPSS1.7%
pct 74
5.9
CVE-2018-16870DEB
It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher at…
2018-01-01Pre-auth
EPSS1.6%
pct 72
7.5
CVE-2020-12457DEB
An issue was discovered in wolfSSL before 4.5.0. It mishandles the change_cipher_spec (CCS) mes…
2020-01-01Pre-auth
EPSS1.5%
pct 71
9.8
CVE-2021-37155DEB
wolfSSL 4.6.x through 4.7.x before 4.8.0 does not produce a failure outcome when the serial num…
2021-01-01Pre-auth
EPSS1.5%
pct 70
7.5
CVE-2022-25640DEB
In wolfSSL before 5.2.0, a TLS 1.3 server cannot properly enforce a requirement for mutual auth…
2022-01-01Pre-auth
EPSS1.3%
pct 67
5.3
CVE-2020-11735DEB
The private-key operations in ecc.c in wolfSSL before 4.4.0 do not use a constant-time modular …
2020-01-01Pre-auth
EPSS1.3%
pct 66
9.1
CVE-2022-23408DEB
wolfSSL 5.x before 5.1.1 uses non-random IV values in certain situations. This affects connecti…
2022-01-01Pre-auth
EPSS1.2%
pct 65
7.5
CVE-2022-34293DEB
wolfSSL before 5.4.0 allows remote attackers to cause a denial of service via DTLS because a ch…
2022-01-01Pre-auth
EPSS1.2%
pct 63
9.8
CVE-2019-16748DEB
In wolfSSL through 4.1.0, there is a missing sanity check of memory accesses in parsing ASN.1 c…
2019-01-01Pre-auth
EPSS1.2%
pct 62
7.5
CVE-2017-8855DEB
wolfSSL before 3.11.0 does not prevent wc_DhAgree from accepting a malformed DH key.
2017-01-01Pre-auth
EPSS1.1%
pct 61
4.9
CVE-2021-24116DEB
In wolfSSL through 4.6.0, a side-channel vulnerability in base64 PEM file decoding allows syste…
2021-01-01
EPSS1.0%
pct 59
9.8
CVE-2019-15651DEB
wolfSSL 4.1.0 has a one-byte heap-based buffer over-read in DecodeCertExtensions in wolfcrypt/s…
2019-01-01Pre-auth
EPSS1.0%
pct 58
5.9
CVE-2014-2903DEB
CyaSSL does not check the key usage extension in leaf certificates, which allows remote attacke…
2014-01-01Pre-auth
EPSS1.0%
pct 56
5.3
CVE-2019-19963DEB
An issue was discovered in wolfSSL before 4.3.0 in a non-default configuration where DSA is ena…
2019-01-01Pre-auth
EPSS1.0%
pct 56
5.3
CVE-2019-19960DEB
In wolfSSL before 4.3.0, wc_ecc_mulmod_ex does not properly resist side-channel attacks.
2019-01-01Pre-auth
EPSS1.0%
pct 56
7.5
CVE-2019-19962DEB
wolfSSL before 4.3.0 mishandles calls to wc_SignatureGenerateHash, leading to fault injection i…
2019-01-01Pre-auth
EPSS0.9%
pct 55
5.3
CVE-2020-24585DEB
An issue was discovered in the DTLS handshake implementation in wolfSSL before 4.5.0. Clear DTL…
2020-01-01Pre-auth
EPSS0.9%
pct 54
7.5
CVE-2014-2904DEB
wolfssl before 3.2.0 has a server certificate that is not properly authorized for server authen…
2014-01-01Pre-auth
EPSS0.9%
pct 54
6.8
CVE-2020-24613DEB
wolfSSL before 4.5.0 mishandles TLS 1.3 server data in the WAIT_CERT_CR state, within SanityChe…
2020-01-01
EPSS0.9%
pct 53
7.5
CVE-2014-2902DEB
wolfssl before 3.2.0 does not properly authorize CA certificate for signing other certificates.
2014-01-01Pre-auth
EPSS0.8%
pct 52
8.1
CVE-2021-3336DEB
DoTls13CertificateVerify in tls13.c in wolfSSL before 4.7.0 does not cease processing for certa…
2021-01-01Pre-auth
EPSS0.8%
pct 51
9.1
CVE-2024-0901ANC
Remotely executed SEGV and out of bounds read allows malicious packet sender to crash or cause …
2024-01-01Pre-auth
EPSS0.7%
pct 48
6.5
CVE-2022-25638DEB
In wolfSSL before 5.2.0, certificate validation may be bypassed during attempted authentication…
2022-01-01Pre-auth
EPSS0.6%
pct 44
Select a vulnerability on the left to open the preview.