Show filters
144 Total Results
Displaying 101-110 of 144
Sort by:
Attacker Value
Unknown
CVE-2019-14431
Disclosure Date: July 29, 2019 (last updated November 27, 2024)
In MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256 bytes and possible Remote Code Execution in parseSSLHandshake in sslDecode.c. During processing of a crafted packet, the server mishandles the fragment length value provided in the DTLS message.
0
Attacker Value
Unknown
CVE-2019-13470
Disclosure Date: July 09, 2019 (last updated November 27, 2024)
MatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.
0
Attacker Value
Unknown
CVE-2019-11842
Disclosure Date: May 09, 2019 (last updated November 27, 2024)
An issue was discovered in Matrix Sydent before 1.0.3 and Synapse before 0.99.3.1. Random number generation is mishandled, which makes it easier for attackers to predict a Sydent authentication token or a Synapse random ID.
0
Attacker Value
Unknown
CVE-2019-11340
Disclosure Date: April 19, 2019 (last updated November 27, 2024)
util/emailutils.py in Matrix Sydent before 1.0.2 mishandles registration restrictions that are based on e-mail domain, if the allowed_local_3pids option is enabled. This occurs because of potentially unwanted behavior in Python, in which an email.utils.parseaddr call on user@bad.example.net@good.example.com returns the user@bad.example.net substring.
0
Attacker Value
Unknown
CVE-2019-10914
Disclosure Date: April 08, 2019 (last updated November 27, 2024)
pubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 certificate verification because of missing validation in psRsaDecryptPubExt in crypto/pubkey/rsa_pub.c.
0
Attacker Value
Unknown
CVE-2019-5885
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
0
Attacker Value
Unknown
CVE-2018-16515
Disclosure Date: September 18, 2018 (last updated November 08, 2023)
Matrix Synapse before 0.33.3.1 allows remote attackers to spoof events and possibly have unspecified other impacts by leveraging improper transaction and event signature validation.
0
Attacker Value
Unknown
CVE-2018-12439
Disclosure Date: June 15, 2018 (last updated November 26, 2024)
MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
0
Attacker Value
Unknown
CVE-2018-12423
Disclosure Date: June 14, 2018 (last updated November 26, 2024)
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
0
Attacker Value
Unknown
CVE-2018-12291
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
The on_get_missing_events function in handlers/federation.py in Matrix Synapse before 0.31.1 has a security bug in the get_missing_events federation API where event visibility rules were not applied correctly.
0