Vulnerabilities > Matrixssl > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-10-03 CVE-2019-13629 Information Exposure Through Discrepancy vulnerability in Matrixssl
MatrixSSL 4.2.1 and earlier contains a timing side channel in ECDSA signature generation.
network
high complexity
matrixssl CWE-203
5.9
2018-06-15 CVE-2018-12439 Information Exposure vulnerability in Matrixssl
MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP.
local
high complexity
matrixssl CWE-200
4.7
2018-01-22 CVE-2017-1000417 Improper Certificate Validation vulnerability in Matrixssl 3.7.2
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g.
network
low complexity
matrixssl CWE-295
5.3
2018-01-09 CVE-2017-1000415 Improper Certificate Validation vulnerability in Matrixssl 3.7.2
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.
network
high complexity
matrixssl CWE-295
5.9
2017-03-03 CVE-2016-6884 Out-of-bounds Read vulnerability in Matrixssl 3.8.2
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.
network
low complexity
matrixssl CWE-125
6.5
2017-03-03 CVE-2016-6883 Information Exposure vulnerability in Matrixssl 3.8.2
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack.
network
high complexity
matrixssl CWE-200
5.9
2017-03-03 CVE-2016-6882 Key Management Errors vulnerability in Matrixssl
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information by conducting a Lenstra side-channel attack.
network
high complexity
matrixssl CWE-320
5.9
2017-01-13 CVE-2016-8671 Information Exposure vulnerability in Matrixssl
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via unspecified vectors.
network
high complexity
matrixssl CWE-200
5.9
2017-01-13 CVE-2016-6887 Information Exposure vulnerability in Matrixssl
The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via a CRT attack.
network
high complexity
matrixssl CWE-200
5.9