Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 35

Количество 35

fstec логотип

BDU:2026-10556

5 месяцев назад

Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260713-73-0035

2 месяца назад

Уязвимость python-relenv

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-28390

5 месяцев назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryp...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-28390

5 месяцев назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-28390

5 месяцев назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-28390

5 месяцев назад

Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-28390

5 месяцев назад

Issue summary: During processing of a crafted CMS EnvelopedData messag ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3443-1

около 2 месяцев назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3272-1

около 2 месяцев назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1711-1

4 месяца назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1605-1

5 месяцев назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1562-1

5 месяцев назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1550-1

5 месяцев назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1549-1

5 месяцев назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1429-1

5 месяцев назад

Security update for openssl-3

EPSS: Низкий
redos логотип

ROS-20260713-80-0036

2 месяца назад

Уязвимость python-relenv

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:38503

2 месяца назад

Moderate: openssl security update

EPSS: Низкий
rocky логотип

RLSA-2026:22315

3 месяца назад

Moderate: compat-openssl10 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22314

3 месяца назад

Moderate: openssl security update

EPSS: Низкий
rocky логотип

RLSA-2026:22313

3 месяца назад

Moderate: compat-openssl11 security update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-10556

Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
5 месяцев назад
redos логотип
ROS-20260713-73-0035

Уязвимость python-relenv

CVSS3: 7.5
1%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-28390

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryp...

CVSS3: 7.5
1%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-28390

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-28390

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
1%
Низкий
5 месяцев назад
msrc логотип
CVE-2026-28390

Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo

CVSS3: 5.9
1%
Низкий
5 месяцев назад
debian логотип
CVE-2026-28390

Issue summary: During processing of a crafted CMS EnvelopedData messag ...

CVSS3: 7.5
1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3443-1

Security update for openssl-1_0_0

1%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:3272-1

Security update for openssl-1_0_0

1%
Низкий
около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1711-1

Security update for openssl-3

1%
Низкий
4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1605-1

Security update for openssl-3

1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1562-1

Security update for openssl-1_1

1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1550-1

Security update for openssl-1_1

1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1549-1

Security update for openssl-1_1

1%
Низкий
5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1429-1

Security update for openssl-3

1%
Низкий
5 месяцев назад
redos логотип
ROS-20260713-80-0036

Уязвимость python-relenv

CVSS3: 7.5
1%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:38503

Moderate: openssl security update

1%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:22315

Moderate: compat-openssl10 security update

1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:22314

Moderate: openssl security update

1%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:22313

Moderate: compat-openssl11 security update

1%
Низкий
3 месяца назад

Уязвимостей на страницу