Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 45

Количество 45

fstec логотип

BDU:2025-12885

10 месяцев назад

Уязвимость компонента FIPS Module криптографической библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260209-73-0011

6 месяцев назад

Уязвимость openssl3

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2025-9230

10 месяцев назад

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-9230

10 месяцев назад

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

CVSS3: 5.6
EPSS: Низкий
nvd логотип

CVE-2025-9230

10 месяцев назад

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2025-9230

10 месяцев назад

Out-of-bounds read & write in RFC 3211 KEK Unwrap

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-9230

10 месяцев назад

Issue summary: An application trying to decrypt CMS messages encrypted ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4126-1

9 месяцев назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3917-1

9 месяцев назад

Security update for openssl-3-livepatches

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:3758-1

9 месяцев назад

Security update for openssl-1_1-livepatches

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03635-1

10 месяцев назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03630-1

10 месяцев назад

Security update for openssl1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03586-1

10 месяцев назад

Security update for openssl-3-livepatches

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03546-1

10 месяцев назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03522-1

10 месяцев назад

Security update for openssl-1_1-livepatches

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03464-1

10 месяцев назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03463-1

10 месяцев назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03443-1

10 месяцев назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03442-1

10 месяцев назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03441-1

10 месяцев назад

Security update for openssl-3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2025-12885

Уязвимость компонента FIPS Module криптографической библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
2%
Низкий
10 месяцев назад
redos логотип
ROS-20260209-73-0011

Уязвимость openssl3

CVSS3: 7.5
2%
Низкий
6 месяцев назад
ubuntu логотип
CVE-2025-9230

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
2%
Низкий
10 месяцев назад
redhat логотип
CVE-2025-9230

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

CVSS3: 5.6
2%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-9230

Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service or Execution of attacker-supplied code. Although the consequences of a successful exploit of this vulnerability could be severe, the probability that the attacker would be able to perform it is low. Besides, password based (PWRI) encryption support in CMS messages is very rarely used. For that reason the issue was assessed as Moderate severity according to our Security Policy. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the CMS implementation is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
2%
Низкий
10 месяцев назад
msrc логотип
CVE-2025-9230

Out-of-bounds read & write in RFC 3211 KEK Unwrap

CVSS3: 7.5
2%
Низкий
10 месяцев назад
debian логотип
CVE-2025-9230

Issue summary: An application trying to decrypt CMS messages encrypted ...

CVSS3: 7.5
2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:4126-1

Security update for openssl-1_0_0

2%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:3917-1

Security update for openssl-3-livepatches

2%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:3758-1

Security update for openssl-1_1-livepatches

2%
Низкий
9 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03635-1

Security update for openssl-1_1

2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03630-1

Security update for openssl1

2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03586-1

Security update for openssl-3-livepatches

2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03546-1

Security update for openssl-3

2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03522-1

Security update for openssl-1_1-livepatches

2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03464-1

Security update for openssl-1_0_0

2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03463-1

Security update for openssl-1_1

2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03443-1

Security update for openssl-1_1

2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03442-1

Security update for openssl-3

2%
Низкий
10 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03441-1

Security update for openssl-3

2%
Низкий
10 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.