Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 35

Количество 35

rocky логотип

RLSA-2026:22312

3 месяца назад

Moderate: openssl security update

EPSS: Низкий
github логотип

GHSA-fgpp-q3px-3xhc

5 месяцев назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-50345

3 месяца назад

ELSA-2026-50345: openssl security fix update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-38503

2 месяца назад

ELSA-2026-38503: openssl security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22315

4 месяца назад

ELSA-2026-22315: compat-openssl10 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22314

около 2 месяцев назад

ELSA-2026-22314: openssl security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22313

3 месяца назад

ELSA-2026-22313: compat-openssl11 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22312

3 месяца назад

ELSA-2026-22312: openssl security update (MODERATE)

EPSS: Низкий
rocky логотип

RLSA-2026:39297

2 месяца назад

Moderate: edk2 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-39297

2 месяца назад

ELSA-2026-39297: edk2 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1577-1

5 месяцев назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1386-1

5 месяцев назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1375-1

5 месяцев назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20525-1

5 месяцев назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3835-1

19 дней назад

Security update for openssl, openssl-3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
rocky логотип
RLSA-2026:22312

Moderate: openssl security update

1%
Низкий
3 месяца назад
github логотип
GHSA-fgpp-q3px-3xhc

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
oracle-oval логотип
ELSA-2026-50345

ELSA-2026-50345: openssl security fix update (MODERATE)

1%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-38503

ELSA-2026-38503: openssl security update (MODERATE)

1%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-22315

ELSA-2026-22315: compat-openssl10 security update (MODERATE)

1%
Низкий
4 месяца назад
oracle-oval логотип
ELSA-2026-22314

ELSA-2026-22314: openssl security update (MODERATE)

1%
Низкий
около 2 месяцев назад
oracle-oval логотип
ELSA-2026-22313

ELSA-2026-22313: compat-openssl11 security update (MODERATE)

1%
Низкий
3 месяца назад
oracle-oval логотип
ELSA-2026-22312

ELSA-2026-22312: openssl security update (MODERATE)

1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:39297

Moderate: edk2 security, bug fix, and enhancement update

2 месяца назад
oracle-oval логотип
ELSA-2026-39297

ELSA-2026-39297: edk2 security, bug fix, and enhancement update (MODERATE)

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1577-1

Security update for openssl-1_1

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1386-1

Security update for openssl-1_1

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1375-1

Security update for openssl-3

5 месяцев назад
suse-cvrf логотип
openSUSE-SU-2026:20525-1

Security update for openssl-3

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3835-1

Security update for openssl, openssl-3

19 дней назад

Уязвимостей на страницу