Vulnerabilities > Matrixssl

DATE CVE VULNERABILITY TITLE RISK
2020-12-30 CVE-2019-16747 Out-of-bounds Write vulnerability in Matrixssl
In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerability than CVE-2019-14431.
network
low complexity
matrixssl CWE-787
5.0
2019-10-03 CVE-2019-13629 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Matrixssl
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.
network
matrixssl CWE-327
4.3
2019-07-29 CVE-2019-14431 Improper Handling of Exceptional Conditions vulnerability in Matrixssl
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c.
network
low complexity
matrixssl CWE-755
7.5
2019-07-09 CVE-2019-13470 Out-of-bounds Read vulnerability in Matrixssl
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
network
low complexity
matrixssl CWE-125
7.5
2019-04-08 CVE-2019-10914 Improper Certificate Validation vulnerability in Matrixssl
pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 certificate verification because of missing validation in psRsaDecryptPubExt in crypto/pubkey/rsa_pub.c.
network
low complexity
matrixssl CWE-295
7.5
2018-06-15 CVE-2018-12439 Information Exposure vulnerability in Matrixssl
MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP.
1.9
2018-01-22 CVE-2017-1000417 Improper Certificate Validation vulnerability in Matrixssl 3.7.2
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g.
network
low complexity
matrixssl CWE-295
5.0
2018-01-09 CVE-2017-1000415 Improper Certificate Validation vulnerability in Matrixssl 3.7.2
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.
network
matrixssl CWE-295
4.3
2017-06-22 CVE-2017-2782 Integer Overflow or Wraparound vulnerability in Matrixssl 3.8.7B
An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
network
low complexity
matrixssl CWE-190
6.4
2017-06-22 CVE-2017-2781 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Matrixssl 3.8.7B
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b.
network
low complexity
matrixssl CWE-119
7.5