Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 32

Количество 32

fstec логотип

BDU:2026-10556

4 месяца назад

Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260713-73-0035

18 дней назад

Уязвимость python-relenv

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-28390

4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryp...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-28390

4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-28390

4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-28390

4 месяца назад

Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-28390

4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData messag ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3272-1

4 дня назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1711-1

3 месяца назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1605-1

3 месяца назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1562-1

3 месяца назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1550-1

3 месяца назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1549-1

3 месяца назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1429-1

3 месяца назад

Security update for openssl-3

EPSS: Низкий
rocky логотип

RLSA-2026:38503

17 дней назад

Moderate: openssl security update

EPSS: Низкий
rocky логотип

RLSA-2026:22315

около 2 месяцев назад

Moderate: compat-openssl10 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22314

около 2 месяцев назад

Moderate: openssl security update

EPSS: Низкий
rocky логотип

RLSA-2026:22313

около 2 месяцев назад

Moderate: compat-openssl11 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22312

около 2 месяцев назад

Moderate: openssl security update

EPSS: Низкий
github логотип

GHSA-fgpp-q3px-3xhc

4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-10556

Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
4 месяца назад
redos логотип
ROS-20260713-73-0035

Уязвимость python-relenv

CVSS3: 7.5
1%
Низкий
18 дней назад
ubuntu логотип
CVE-2026-28390

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryp...

CVSS3: 7.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-28390

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-28390

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-28390

Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo

CVSS3: 5.9
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-28390

Issue summary: During processing of a crafted CMS EnvelopedData messag ...

CVSS3: 7.5
1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3272-1

Security update for openssl-1_0_0

1%
Низкий
4 дня назад
suse-cvrf логотип
SUSE-SU-2026:1711-1

Security update for openssl-3

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1605-1

Security update for openssl-3

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1562-1

Security update for openssl-1_1

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1550-1

Security update for openssl-1_1

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1549-1

Security update for openssl-1_1

1%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1429-1

Security update for openssl-3

1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:38503

Moderate: openssl security update

1%
Низкий
17 дней назад
rocky логотип
RLSA-2026:22315

Moderate: compat-openssl10 security update

1%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:22314

Moderate: openssl security update

1%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:22313

Moderate: compat-openssl11 security update

1%
Низкий
около 2 месяцев назад
rocky логотип
RLSA-2026:22312

Moderate: openssl security update

1%
Низкий
около 2 месяцев назад
github логотип
GHSA-fgpp-q3px-3xhc

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
1%
Низкий
4 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.