Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 22

Количество 22

github логотип

GHSA-7x88-9hgc-69gf

4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-28389

4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in D...

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-28389

4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-28389

4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-28389

3 месяца назад

Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-28389

4 месяца назад

Issue summary: During processing of a crafted CMS EnvelopedData messag ...

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2026-10555

4 месяца назад

Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260713-73-0036

18 дней назад

Уязвимость python-relenv

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1290-1

4 месяца назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1255-1

4 месяца назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1577-1

3 месяца назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1386-1

4 месяца назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1291-1

4 месяца назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1257-1

4 месяца назад

Security update for openssl-1_1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1256-1

4 месяца назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1215-1

4 месяца назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1214-1

4 месяца назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1213-1

4 месяца назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1375-1

4 месяца назад

Security update for openssl-3

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20525-1

4 месяца назад

Security update for openssl-3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7x88-9hgc-69gf

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
1%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-28389

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in D...

CVSS3: 7.5
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-28389

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 5.9
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-28389

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientInfo is processed, the optional parameters field of KeyEncryptionAlgorithmIdentifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

CVSS3: 7.5
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-28389

Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo

CVSS3: 7.5
1%
Низкий
3 месяца назад
debian логотип
CVE-2026-28389

Issue summary: During processing of a crafted CMS EnvelopedData messag ...

CVSS3: 7.5
1%
Низкий
4 месяца назад
fstec логотип
BDU:2026-10555

Уязвимость инструмента для создания воспроизводимых и перемещаемых окружений Python relenv, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
4 месяца назад
redos логотип
ROS-20260713-73-0036

Уязвимость python-relenv

CVSS3: 7.5
1%
Низкий
18 дней назад
suse-cvrf логотип
SUSE-SU-2026:1290-1

Security update for openssl-1_1

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1255-1

Security update for openssl-1_1

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1577-1

Security update for openssl-1_1

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1386-1

Security update for openssl-1_1

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1291-1

Security update for openssl-1_0_0

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1257-1

Security update for openssl-1_1

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1256-1

Security update for openssl-1_0_0

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1215-1

Security update for openssl-3

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1214-1

Security update for openssl-3

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1213-1

Security update for openssl-3

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1375-1

Security update for openssl-3

4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20525-1

Security update for openssl-3

4 месяца назад

Уязвимостей на страницу