Show filters
144 Total Results
Displaying 101-110 of 144
Sort by:
Attacker Value
Unknown

CVE-2019-14431

Disclosure Date: July 29, 2019 (last updated November 27, 2024)
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c. During processing of a crafted packet, the server mishandles the fragment length value provided in the DTLS message.
Attacker Value
Unknown

CVE-2019-13470

Disclosure Date: July 09, 2019 (last updated November 27, 2024)
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
0
Attacker Value
Unknown

CVE-2019-11842

Disclosure Date: May 09, 2019 (last updated November 27, 2024)
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
0
Attacker Value
Unknown

CVE-2019-11340

Disclosure Date: April 19, 2019 (last updated November 27, 2024)
util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns the user@bad.example.net substring.
0
Attacker Value
Unknown

CVE-2019-10914

Disclosure Date: April 08, 2019 (last updated November 27, 2024)
pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 certificate verification because of missing validation in psRsaDecryptPubExt in crypto/pubkey/rsa_pub.c.
0
Attacker Value
Unknown

CVE-2019-5885

Disclosure Date: March 21, 2019 (last updated November 08, 2023)
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
0
Attacker Value
Unknown

CVE-2018-16515

Disclosure Date: September 18, 2018 (last updated November 08, 2023)
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
0
Attacker Value
Unknown

CVE-2018-12439

Disclosure Date: June 15, 2018 (last updated November 26, 2024)
MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
0
Attacker Value
Unknown

CVE-2018-12423

Disclosure Date: June 14, 2018 (last updated November 26, 2024)
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
0
Attacker Value
Unknown

CVE-2018-12291

Disclosure Date: June 13, 2018 (last updated November 26, 2024)
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.
0