43 entries matching openssl — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-41447 | FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbit | HIGH | 8.5 | 2%ile | NVD | 2026-08-03 |
| CVE-2026-69247 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 unti | HIGH | 8.2 | 7%ile | NVD | 2026-08-03 |
| CVE-2026-66402 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in | CRITICAL | 9.3 | 21%ile | NVD | 2026-08-01 |
| CVE-2026-67293 | FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. | CRITICAL | 9.3 | 6%ile | NVD | 2026-08-01 |
| USN-8625-1 | USN-8625-1: OpenSSL vulnerability | UNKNOWN | — | — | Ubuntu | 2026-07-30 |
| CVE-2026-59847 | Libssh: libssh: integrity downgrade via openssl aes-gcm tag verification | MEDIUM | 5.9 | 23%ile | Microsoft | 2026-07-14 |
| CVE-2026-14355 | ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD | MEDIUM | 5.6 | 20%ile | Microsoft | 2026-07-14 |
| CVE-2026-45784 | rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers | UNKNOWN | — | 3%ile | Microsoft | 2026-07-14 |
| CVE-2026-34182 | CMS AuthEnvelopedData Processing May Accept Forged Messages | CRITICAL | 9.1 | 28%ile | Microsoft | 2026-06-09 |
| CVE-2026-7383 | Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion | HIGH | 8.1 | 47%ile | Microsoft | 2026-06-09 |
| CVE-2026-45445 | AES-OCB IV Ignored on EVP_Cipher() Path | HIGH | 7.5 | 46%ile | Microsoft | 2026-06-09 |
| CVE-2026-34183 | Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler | HIGH | 7.5 | 61%ile | Microsoft | 2026-06-09 |
| CVE-2026-9076 | Out-of-Bounds Read in CMS Password-Based Decryption | HIGH | 7.5 | 45%ile | Microsoft | 2026-06-09 |
| CVE-2026-34180 | Heap Buffer Over-read in ASN.1 Content Parsing | HIGH | 7.5 | 60%ile | Microsoft | 2026-06-09 |
| CVE-2026-42766 | Possible NULL Dereference in Password-Based CMS Decryption | MEDIUM | 5.9 | 59%ile | Microsoft | 2026-06-09 |
| CVE-2026-42767 | NULL Pointer Dereference in CRMF EncryptedValue Decryption | MEDIUM | 5.9 | 43%ile | Microsoft | 2026-06-09 |
| CVE-2026-45446 | Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes | MEDIUM | 4.8 | 29%ile | Microsoft | 2026-06-09 |
| CVE-2026-42768 | Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() | LOW | 3.7 | 44%ile | Microsoft | 2026-06-09 |
| CVE-2026-44662 | rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding | UNKNOWN | — | 7%ile | Microsoft | 2026-05-12 |
| CVE-2025-14575 | Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loading | UNKNOWN | — | 1%ile | Microsoft | 2026-05-12 |
| CVE-2026-28387 | Potential Use-after-free in DANE Client Code | HIGH | 8.1 | 53%ile | Microsoft | 2026-04-14 |
| CVE-2026-28388 | NULL Pointer Dereference When Processing a Delta CRL | HIGH | 7.5 | 61%ile | Microsoft | 2026-04-14 |
| CVE-2026-28389 | Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo | HIGH | 7.5 | 60%ile | Microsoft | 2026-04-14 |
| CVE-2026-28390 | Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo | HIGH | 7.5 | 60%ile | Microsoft | 2026-04-14 |
| CVE-2026-31789 | Heap Buffer Overflow in Hexadecimal Conversion | HIGH | 7.3 | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-31790 | Incorrect Failure Handling in RSA KEM RSASVE Encapsulation | MEDIUM | 6.5 | 65%ile | Microsoft | 2026-04-14 |
| CVE-2026-41676 | rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1 | UNKNOWN | — | 21%ile | Microsoft | 2026-04-14 |
| CVE-2026-41678 | rust-openssl: Incorrect bounds assertion in aes key wrap | UNKNOWN | — | 16%ile | Microsoft | 2026-04-14 |
| CVE-2026-41681 | rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check | UNKNOWN | — | 29%ile | Microsoft | 2026-04-14 |
| CVE-2026-41898 | rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjace | UNKNOWN | — | 20%ile | Microsoft | 2026-04-14 |
| CVE-2026-41677 | rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length | UNKNOWN | — | 22%ile | Microsoft | 2026-04-14 |
| CVE-2025-9230 | Out-of-bounds read & write in RFC 3211 KEK Unwrap | HIGH | 7.5 | 76%ile | Microsoft | 2025-09-09 |
| CVE-2025-9231 | Timing side-channel in SM2 algorithm on 64 bit ARM | MEDIUM | 6.5 | 81%ile | Microsoft | 2025-09-09 |
| CVE-2025-9232 | Out-of-bounds read in HTTP client no_proxy handling | MEDIUM | 5.9 | 81%ile | Microsoft | 2025-09-09 |
| CVE-2025-60018 | Glib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certific | MEDIUM | 4.8 | 21%ile | Microsoft | 2025-09-09 |
| CVE-2025-60019 | Glib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via | LOW | 3.7 | 26%ile | Microsoft | 2025-09-09 |
| CVE-2025-5987 | Libssh: invalid return code for chacha20 poly1305 with openssl backend | MEDIUM | 5.0 | 71%ile | Microsoft | 2025-07-08 |
| CVE-2023-53159 | The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_ho | MEDIUM | 4.5 | 26%ile | Microsoft | 2025-07-08 |
| CVE-2025-7394 | In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to | UNKNOWN | — | 31%ile | Microsoft | 2025-07-08 |
| CVE-2024-26306 | iPerf3 before 3.17 when used with OpenSSL before 3.2.0 as a server with RSA authentication allows a timing side channel | MEDIUM | 5.9 | 62%ile | Microsoft | 2024-05-14 |
| CVE-2024-4603 | Excessive time spent checking DSA keys and parameters | MEDIUM | 5.3 | 63%ile | Microsoft | 2024-05-14 |
| CVE-2023-6237 | Excessive time spent checking invalid RSA public keys | MEDIUM | 5.9 | 82%ile | Microsoft | 2024-04-09 |
| CVE-2024-2511 | Unbounded memory growth with session handling in TLSv1.3 | MEDIUM | 5.9 | 99%ile | Microsoft | 2024-04-09 |