← Back to feed Search feed

OpenSSL vulnerabilities

43 entries matching openssl — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-41447FirmaCheck for Windows before 1.3.16 contains a dll hijacking vulnerability that allows local attackers to execute arbitHIGH8.52%ileNVD2026-08-03
CVE-2026-69247cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 untiHIGH8.27%ileNVD2026-08-03
CVE-2026-66402FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in CRITICAL9.321%ileNVD2026-08-01
CVE-2026-67293FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains an improper certificate hostname validation vulnerability. CRITICAL9.36%ileNVD2026-08-01
USN-8625-1USN-8625-1: OpenSSL vulnerabilityUNKNOWNUbuntu2026-07-30
CVE-2026-59847Libssh: libssh: integrity downgrade via openssl aes-gcm tag verificationMEDIUM5.923%ileMicrosoft2026-07-14
CVE-2026-14355ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PADMEDIUM5.620%ileMicrosoft2026-07-14
CVE-2026-45784rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphersUNKNOWN3%ileMicrosoft2026-07-14
CVE-2026-34182CMS AuthEnvelopedData Processing May Accept Forged MessagesCRITICAL9.128%ileMicrosoft2026-06-09
CVE-2026-7383Possible Heap Buffer Overflow in ASN.1 Multibyte String ConversionHIGH8.147%ileMicrosoft2026-06-09
CVE-2026-45445AES-OCB IV Ignored on EVP_Cipher() PathHIGH7.546%ileMicrosoft2026-06-09
CVE-2026-34183Unbounded Memory Growth in the QUIC PATH_CHALLENGE HandlerHIGH7.561%ileMicrosoft2026-06-09
CVE-2026-9076Out-of-Bounds Read in CMS Password-Based DecryptionHIGH7.545%ileMicrosoft2026-06-09
CVE-2026-34180Heap Buffer Over-read in ASN.1 Content ParsingHIGH7.560%ileMicrosoft2026-06-09
CVE-2026-42766Possible NULL Dereference in Password-Based CMS DecryptionMEDIUM5.959%ileMicrosoft2026-06-09
CVE-2026-42767NULL Pointer Dereference in CRMF EncryptedValue DecryptionMEDIUM5.943%ileMicrosoft2026-06-09
CVE-2026-45446Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modesMEDIUM4.829%ileMicrosoft2026-06-09
CVE-2026-42768Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()LOW3.744%ileMicrosoft2026-06-09
CVE-2026-44662rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-paddingUNKNOWN7%ileMicrosoft2026-05-12
CVE-2025-14575Uncontrolled Search Path Element in Qt Network OpenSSL TLS backend allows rogue CA certificate loadingUNKNOWN1%ileMicrosoft2026-05-12
CVE-2026-28387Potential Use-after-free in DANE Client CodeHIGH8.153%ileMicrosoft2026-04-14
CVE-2026-28388NULL Pointer Dereference When Processing a Delta CRLHIGH7.561%ileMicrosoft2026-04-14
CVE-2026-28389Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfoHIGH7.560%ileMicrosoft2026-04-14
CVE-2026-28390Possible NULL Dereference When Processing CMS KeyTransportRecipientInfoHIGH7.560%ileMicrosoft2026-04-14
CVE-2026-31789Heap Buffer Overflow in Hexadecimal ConversionHIGH7.316%ileMicrosoft2026-04-14
CVE-2026-31790Incorrect Failure Handling in RSA KEM RSASVE EncapsulationMEDIUM6.565%ileMicrosoft2026-04-14
CVE-2026-41676rust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1UNKNOWN21%ileMicrosoft2026-04-14
CVE-2026-41678rust-openssl: Incorrect bounds assertion in aes key wrapUNKNOWN16%ileMicrosoft2026-04-14
CVE-2026-41681rust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length checkUNKNOWN29%ileMicrosoft2026-04-14
CVE-2026-41898rust-openssl: Unchecked callback-returned length in PSK and cookie generate trampolines can cause OpenSSL to leak adjaceUNKNOWN20%ileMicrosoft2026-04-14
CVE-2026-41677rust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized lengthUNKNOWN22%ileMicrosoft2026-04-14
CVE-2025-9230Out-of-bounds read & write in RFC 3211 KEK UnwrapHIGH7.576%ileMicrosoft2025-09-09
CVE-2025-9231Timing side-channel in SM2 algorithm on 64 bit ARMMEDIUM6.581%ileMicrosoft2025-09-09
CVE-2025-9232Out-of-bounds read in HTTP client no_proxy handlingMEDIUM5.981%ileMicrosoft2025-09-09
CVE-2025-60018Glib-networking: out of bound reads on glib-networking through tls/openssl/gtlscertificate-openssl.c via "g_tls_certificMEDIUM4.821%ileMicrosoft2025-09-09
CVE-2025-60019Glib-networking: uninitialized memory dereferences on glib-networking through glib-networking/tls/openssl/gtlsbio.c via LOW3.726%ileMicrosoft2025-09-09
CVE-2025-5987Libssh: invalid return code for chacha20 poly1305 with openssl backendMEDIUM5.071%ileMicrosoft2025-07-08
CVE-2023-53159The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_hoMEDIUM4.526%ileMicrosoft2025-07-08
CVE-2025-7394In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to UNKNOWN31%ileMicrosoft2025-07-08
CVE-2024-26306iPerf3 before 3.17 when used with OpenSSL before 3.2.0 as a server with RSA authentication allows a timing side channel MEDIUM5.962%ileMicrosoft2024-05-14
CVE-2024-4603Excessive time spent checking DSA keys and parametersMEDIUM5.363%ileMicrosoft2024-05-14
CVE-2023-6237Excessive time spent checking invalid RSA public keysMEDIUM5.982%ileMicrosoft2024-04-09
CVE-2024-2511Unbounded memory growth with session handling in TLSv1.3MEDIUM5.999%ileMicrosoft2024-04-09