Search CVE reports
2511 – 2520 of 35263 results
Stack Buffer Overflow in wc_HpkeLabeledExtract via Oversized ECH Config. A vulnerability existed in wolfSSL 5.8.4 ECH (Encrypted Client Hello) support, where a maliciously crafted ECH config could cause a stack buffer overflow on...
1 affected package
wolfssl
| Package | 24.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
Heap Overflow in TLS 1.3 ECH parsing. An integer underflow existed in ECH extension parsing logic when calculating a buffer length, which resulted in writing beyond the bounds of an allocated buffer. Note that in wolfSSL, ECH is...
1 affected package
wolfssl
| Package | 24.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
Out-of-bounds read in ALPN parsing due to incomplete validation. wolfSSL 5.8.4 and earlier contained an out-of-bounds read in ALPN handling when built with ALPN enabled (HAVE_ALPN / --enable-alpn). A crafted ALPN protocol list...
1 affected package
wolfssl
| Package | 24.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
Missing required cryptographic step in the TLS 1.3 client HelloRetryRequest handshake logic in wolfSSL could lead to a compromise in the confidentiality of TLS-protected communications via a crafted HelloRetryRequest followed by a...
1 affected package
wolfssl
| Package | 24.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
An integer overflow vulnerability existed in the static function wolfssl_add_to_chain, that caused heap corruption when certificate data was written out of bounds of an insufficiently sized certificate buffer. wolfssl_add_to_chain...
1 affected package
wolfssl
| Package | 24.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning Access-Control-Allow-Credentials: true, effectively allowing...
1 affected package
qbittorrent
| Package | 24.04 LTS |
|---|---|
| qbittorrent | Needs evaluation |
Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue...
1 affected package
golang-github-smallstep-certificates
| Package | 24.04 LTS |
|---|---|
| golang-github-smallstep-certificates | Needs evaluation |
ormar is a async mini ORM for Python. Versions 0.23.0 and below are vulnerable to Pydantic validation bypass through the model constructor, allowing any unauthenticated user to skip all field validation by injecting "__pk_only__":...
1 affected package
ormar
| Package | 24.04 LTS |
|---|---|
| ormar | Needs evaluation |
In wolfSSL 5.8.4, constant-time masking logic in sp_256_get_entry_256_9 is optimized into conditional branches (bnez) by GCC when targeting RISC-V RV32I with -O3. This transformation breaks the side-channel resistance of ECC...
1 affected package
wolfssl
| Package | 24.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
wolfSSL 5.8.4 on RISC-V RV32I architectures lacks a constant-time software implementation for 64-bit multiplication. The compiler-inserted __muldi3 subroutine executes in variable time based on operand values. This...
1 affected package
wolfssl
| Package | 24.04 LTS |
|---|---|
| wolfssl | Needs evaluation |