Vulnerabilities > Matrixssl

DATE CVE VULNERABILITY TITLE RISK
2017-01-13 CVE-2016-6885 Use After Free vulnerability in Matrixssl 3.8.2/3.8.3
The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base zero value for the modular exponentiation.
network
low complexity
matrixssl CWE-416
7.5
2017-01-05 CVE-2016-6892 Use After Free vulnerability in Matrixssl
The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory) via a crafted X.509 certificate.
network
low complexity
matrixssl CWE-416
7.5
2017-01-05 CVE-2016-6891 Out-of-bounds Read vulnerability in Matrixssl
MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in an X.509 certificate.
network
low complexity
matrixssl CWE-125
7.5
2017-01-05 CVE-2016-6890 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Matrixssl
Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an X.509 certificate.
network
low complexity
matrixssl CWE-119
critical
9.8