Количество 25
Количество 25
BDU:2026-11013
Уязвимость функции RSA_public_encrypt() микропрограммного обеспечения коммуникационного шлюза SIMATIC CN 4100, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации
CVE-2026-31790
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i...
CVE-2026-31790
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i...
CVE-2026-31790
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i
CVE-2026-31790
Incorrect Failure Handling in RSA KEM RSASVE Encapsulation
CVE-2026-31790
Issue summary: Applications using RSASVE key encapsulation to establis ...
ROS-20260713-80-0031
Уязвимость python-relenv
ROS-20260713-73-0030
Уязвимость python-relenv
RLSA-2026:19218
Moderate: openssl security update
RLSA-2026:19066
Moderate: openssl security update
GHSA-vgxx-5xj5-q97x
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacke...
ELSA-2026-500005
ELSA-2026-500005: openssl security update (MODERATE)
ELSA-2026-27744
ELSA-2026-27744: openssl-fips-provider security update (MODERATE)
ELSA-2026-19218
ELSA-2026-19218: openssl security update (MODERATE)
ELSA-2026-19066
ELSA-2026-19066: openssl security update (MODERATE)
RLSA-2026:39297
Moderate: edk2 security, bug fix, and enhancement update
ELSA-2026-39297
ELSA-2026-39297: edk2 security, bug fix, and enhancement update (MODERATE)
SUSE-SU-2026:1291-1
Security update for openssl-1_0_0
SUSE-SU-2026:1257-1
Security update for openssl-1_1
SUSE-SU-2026:1256-1
Security update for openssl-1_0_0
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-11013 Уязвимость функции RSA_public_encrypt() микропрограммного обеспечения коммуникационного шлюза SIMATIC CN 4100, позволяющая нарушителю оказать воздействие на конфиденциальность защищаемой информации | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-31790 Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i... | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-31790 Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i... | CVSS3: 5.9 | 1% Низкий | 5 месяцев назад | |
CVE-2026-31790 Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacker i | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-31790 Incorrect Failure Handling in RSA KEM RSASVE Encapsulation | CVSS3: 6.5 | 1% Низкий | 5 месяцев назад | |
CVE-2026-31790 Issue summary: Applications using RSASVE key encapsulation to establis ... | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
ROS-20260713-80-0031 Уязвимость python-relenv | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
ROS-20260713-73-0030 Уязвимость python-relenv | CVSS3: 7.5 | 1% Низкий | 2 месяца назад | |
RLSA-2026:19218 Moderate: openssl security update | 1% Низкий | 4 месяца назад | ||
RLSA-2026:19066 Moderate: openssl security update | 1% Низкий | 4 месяца назад | ||
GHSA-vgxx-5xj5-q97x Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt() returns the number of bytes written on success and -1 on error. The affected code tests only whether the return value is non-zero. As a result, if RSA encryption fails, encapsulation can still return success to the caller, set the output lengths, and leave the caller to use the contents of the ciphertext buffer as if a valid KEM ciphertext had been produced. If applications use EVP_PKEY_encapsulate() with RSA/RSASVE on an attacker-supplied invalid RSA public key without first validating that key, then this may cause stale or uninitialized contents of the caller-provided ciphertext buffer to be disclosed to the attacke... | CVSS3: 7.5 | 1% Низкий | 5 месяцев назад | |
ELSA-2026-500005 ELSA-2026-500005: openssl security update (MODERATE) | 1% Низкий | 2 месяца назад | ||
ELSA-2026-27744 ELSA-2026-27744: openssl-fips-provider security update (MODERATE) | 1% Низкий | 18 дней назад | ||
ELSA-2026-19218 ELSA-2026-19218: openssl security update (MODERATE) | 1% Низкий | 3 месяца назад | ||
ELSA-2026-19066 ELSA-2026-19066: openssl security update (MODERATE) | 1% Низкий | 2 месяца назад | ||
RLSA-2026:39297 Moderate: edk2 security, bug fix, and enhancement update | 2 месяца назад | |||
ELSA-2026-39297 ELSA-2026-39297: edk2 security, bug fix, and enhancement update (MODERATE) | 2 месяца назад | |||
SUSE-SU-2026:1291-1 Security update for openssl-1_0_0 | 5 месяцев назад | |||
SUSE-SU-2026:1257-1 Security update for openssl-1_1 | 5 месяцев назад | |||
SUSE-SU-2026:1256-1 Security update for openssl-1_0_0 | 5 месяцев назад |
Уязвимостей на страницу