Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 19

Количество 19

fstec логотип

BDU:2024-06735

почти 2 года назад

Уязвимость библиотеки OpenSSL, связанная с прочтением неверного адреса в памяти при сравнении имен субъекта `otherName` сертификата X.509, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
EPSS: Средний
redos логотип

ROS-20250113-01

больше 1 года назад

Уязвимость edk2-tools

CVSS3: 5.9
EPSS: Средний
redos логотип

ROS-20241001-05

почти 2 года назад

Множественные уязвимости openssl3

CVSS3: 9.1
EPSS: Низкий
ubuntu логотип

CVE-2024-6119

почти 2 года назад

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected ident...

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2024-6119

почти 2 года назад

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected ident...

CVSS3: 5.9
EPSS: Средний
nvd логотип

CVE-2024-6119

почти 2 года назад

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected iden

CVSS3: 7.5
EPSS: Средний
msrc логотип

CVE-2024-6119

почти 2 года назад

Possible denial of service in X.509 name checks

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2024-6119

почти 2 года назад

Issue summary: Applications performing certificate name checks (e.g., ...

CVSS3: 7.5
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2025:1516-1

около 1 года назад

Security update for openssl-3

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:3107-1

почти 2 года назад

Security update for openssl-3

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:3106-1

почти 2 года назад

Security update for openssl-3

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2024:3105-1

почти 2 года назад

Security update for openssl-3

EPSS: Средний
rocky логотип

RLSA-2024:8935

больше 1 года назад

Moderate: edk2 security update

EPSS: Средний
rocky логотип

RLSA-2024:6783

почти 2 года назад

Moderate: openssl security update

EPSS: Средний
github логотип

GHSA-7m4m-pwhv-49c5

почти 2 года назад

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected i...

CVSS3: 7.5
EPSS: Средний
oracle-oval логотип

ELSA-2024-8935

больше 1 года назад

ELSA-2024-8935: edk2 security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-6783

почти 2 года назад

ELSA-2024-6783: openssl security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-12683

почти 2 года назад

ELSA-2024-12683: openssl security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-12675

почти 2 года назад

ELSA-2024-12675: openssl security update (MODERATE)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2024-06735

Уязвимость библиотеки OpenSSL, связанная с прочтением неверного адреса в памяти при сравнении имен субъекта `otherName` сертификата X.509, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.9
67%
Средний
почти 2 года назад
redos логотип
ROS-20250113-01

Уязвимость edk2-tools

CVSS3: 5.9
67%
Средний
больше 1 года назад
redos логотип
ROS-20241001-05

Множественные уязвимости openssl3

CVSS3: 9.1
почти 2 года назад
ubuntu логотип
CVE-2024-6119

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected ident...

CVSS3: 7.5
67%
Средний
почти 2 года назад
redhat логотип
CVE-2024-6119

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected ident...

CVSS3: 5.9
67%
Средний
почти 2 года назад
nvd логотип
CVE-2024-6119

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected iden

CVSS3: 7.5
67%
Средний
почти 2 года назад
msrc логотип
CVE-2024-6119

Possible denial of service in X.509 name checks

CVSS3: 7.5
67%
Средний
почти 2 года назад
debian логотип
CVE-2024-6119

Issue summary: Applications performing certificate name checks (e.g., ...

CVSS3: 7.5
67%
Средний
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2025:1516-1

Security update for openssl-3

67%
Средний
около 1 года назад
suse-cvrf логотип
SUSE-SU-2024:3107-1

Security update for openssl-3

67%
Средний
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3106-1

Security update for openssl-3

67%
Средний
почти 2 года назад
suse-cvrf логотип
SUSE-SU-2024:3105-1

Security update for openssl-3

67%
Средний
почти 2 года назад
rocky логотип
RLSA-2024:8935

Moderate: edk2 security update

67%
Средний
больше 1 года назад
rocky логотип
RLSA-2024:6783

Moderate: openssl security update

67%
Средний
почти 2 года назад
github логотип
GHSA-7m4m-pwhv-49c5

Issue summary: Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address resulting in abnormal termination of the application process. Impact summary: Abnormal termination of an application can a cause a denial of service. Applications performing certificate name checks (e.g., TLS clients checking server certificates) may attempt to read an invalid memory address when comparing the expected name with an `otherName` subject alternative name of an X.509 certificate. This may result in an exception that terminates the application program. Note that basic certificate chain validation (signatures, dates, ...) is not affected, the denial of service can occur only when the application also specifies an expected DNS name, Email address or IP address. TLS servers rarely solicit client certificates, and even when they do, they generally don't perform a name check against a reference identifier (expected i...

CVSS3: 7.5
67%
Средний
почти 2 года назад
oracle-oval логотип
ELSA-2024-8935

ELSA-2024-8935: edk2 security update (MODERATE)

больше 1 года назад
oracle-oval логотип
ELSA-2024-6783

ELSA-2024-6783: openssl security update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2024-12683

ELSA-2024-12683: openssl security update (MODERATE)

почти 2 года назад
oracle-oval логотип
ELSA-2024-12675

ELSA-2024-12675: openssl security update (MODERATE)

почти 2 года назад

Уязвимостей на страницу