Show filters
144 Total Results
Displaying 111-120 of 144
Sort by:
Attacker Value
Unknown
CVE-2018-10657
Disclosure Date: May 02, 2018 (last updated November 26, 2024)
Matrix Synapse before 0.28.1 is prone to a denial of service flaw where malicious events injected with depth = 2^63 - 1 render rooms unusable, related to federation/federation_base.py and handlers/message.py, as exploited in the wild in April 2018.
0
Attacker Value
Unknown
CVE-2017-1000417
Disclosure Date: January 22, 2018 (last updated November 26, 2024)
MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.
0
Attacker Value
Unknown
CVE-2017-1000415
Disclosure Date: January 09, 2018 (last updated November 26, 2024)
MatrixSSL version 3.7.2 has an incorrect UTCTime date range validation in its X.509 certificate validation process resulting in some certificates have their expiration (beginning) year extended (delayed) by 100 years.
0
Attacker Value
Unknown
CVE-2017-17636
Disclosure Date: December 13, 2017 (last updated November 26, 2024)
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
0
Attacker Value
Unknown
CVE-2017-1000007
Disclosure Date: July 17, 2017 (last updated November 26, 2024)
txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.
0
Attacker Value
Unknown
CVE-2017-2782
Disclosure Date: June 22, 2017 (last updated November 26, 2024)
An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection
0
Attacker Value
Unknown
CVE-2017-2780
Disclosure Date: June 22, 2017 (last updated November 26, 2024)
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection.
0
Attacker Value
Unknown
CVE-2017-2781
Disclosure Date: June 22, 2017 (last updated November 26, 2024)
An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection.
0
Attacker Value
Unknown
CVE-2016-6884
Disclosure Date: March 03, 2017 (last updated November 26, 2024)
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.
0
Attacker Value
Unknown
CVE-2016-6882
Disclosure Date: March 03, 2017 (last updated November 26, 2024)
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information by conducting a Lenstra side-channel attack.
0