Логотип exploitDog
bind:"CVE-2023-6129" OR bind:"CVE-2023-6237" OR bind:"CVE-2024-0727" OR bind:"CVE-2024-1298"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-6129" OR bind:"CVE-2023-6237" OR bind:"CVE-2024-0727" OR bind:"CVE-2024-1298"

Количество 56

Количество 56

ubuntu логотип

CVE-2024-1298

больше 1 года назад

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
EPSS: Низкий
redhat логотип

CVE-2024-1298

больше 1 года назад

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
EPSS: Низкий
nvd логотип

CVE-2024-1298

больше 1 года назад

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
EPSS: Низкий
msrc логотип

CVE-2024-1298

больше 1 года назад

CVSS3: 6
EPSS: Низкий
debian логотип

CVE-2024-1298

больше 1 года назад

EDK2 contains a vulnerability when S3 sleep is activated where an Atta ...

CVSS3: 6
EPSS: Низкий
ubuntu логотип

CVE-2024-0727

почти 2 года назад

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant...

CVSS3: 5.5
EPSS: Низкий
redhat логотип

CVE-2024-0727

почти 2 года назад

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2024-0727

почти 2 года назад

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significan

CVSS3: 5.5
EPSS: Низкий
msrc логотип

CVE-2024-0727

почти 2 года назад

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2024-0727

почти 2 года назад

Issue summary: Processing a maliciously formatted PKCS12 file may lead ...

CVSS3: 5.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:02516-1

4 месяца назад

Security update for ovmf

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:4088-1

12 месяцев назад

Security update for ovmf

EPSS: Низкий
github логотип

GHSA-xvcj-qw55-xx42

больше 1 года назад

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
EPSS: Низкий
fstec логотип

BDU:2025-12007

больше 1 года назад

Уязвимость компонента FirmwarePerformancePei.c среды с открытым исходным кодом для разработки UEFI EDK2, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0842-1

больше 1 года назад

Security update for openssl

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0841-1

больше 1 года назад

Security update for openssl1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0840-1

больше 1 года назад

Security update for compat-openssl098

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0833-1

больше 1 года назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0832-1

больше 1 года назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0831-1

больше 1 года назад

Security update for openssl-1_0_0

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-1298

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2024-1298

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-1298

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
0%
Низкий
больше 1 года назад
msrc логотип
CVSS3: 6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-1298

EDK2 contains a vulnerability when S3 sleep is activated where an Atta ...

CVSS3: 6
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2024-0727

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
redhat логотип
CVE-2024-0727

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-0727

Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significan

CVSS3: 5.5
0%
Низкий
почти 2 года назад
msrc логотип
CVSS3: 5.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-0727

Issue summary: Processing a maliciously formatted PKCS12 file may lead ...

CVSS3: 5.5
0%
Низкий
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2025:02516-1

Security update for ovmf

0%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2024:4088-1

Security update for ovmf

0%
Низкий
12 месяцев назад
github логотип
GHSA-xvcj-qw55-xx42

EDK2 contains a vulnerability when S3 sleep is activated where an Attacker may cause a Division-By-Zero due to a UNIT32 overflow via local access. A successful exploit of this vulnerability may lead to a loss of Availability.

CVSS3: 6
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2025-12007

Уязвимость компонента FirmwarePerformancePei.c среды с открытым исходным кодом для разработки UEFI EDK2, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0842-1

Security update for openssl

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0841-1

Security update for openssl1

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0840-1

Security update for compat-openssl098

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0833-1

Security update for openssl-1_1

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0832-1

Security update for openssl-1_1

0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2024:0831-1

Security update for openssl-1_0_0

0%
Низкий
больше 1 года назад

Уязвимостей на страницу