Show filters
68 Total Results
Displaying 21-30 of 68
Sort by:
Attacker Value
Unknown
CVE-2009-5144
Disclosure Date: February 03, 2018 (last updated November 26, 2024)
mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.
0
Attacker Value
Unknown
CVE-2016-4456
Disclosure Date: August 08, 2017 (last updated November 26, 2024)
The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem.
0
Attacker Value
Unknown
CVE-2017-7507
Disclosure Date: June 16, 2017 (last updated November 26, 2024)
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.
0
Attacker Value
Unknown
CVE-2017-7869
Disclosure Date: April 14, 2017 (last updated November 26, 2024)
GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function in opencdk/read-packet.c. This issue (which is a subset of the vendor's GNUTLS-SA-2017-3 report) is fixed in 3.5.10.
0
Attacker Value
Unknown
CVE-2017-5337
Disclosure Date: March 24, 2017 (last updated November 26, 2024)
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
0
Attacker Value
Unknown
CVE-2017-5336
Disclosure Date: March 24, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
0
Attacker Value
Unknown
CVE-2017-5335
Disclosure Date: March 24, 2017 (last updated November 26, 2024)
The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.
0
Attacker Value
Unknown
CVE-2017-5334
Disclosure Date: March 24, 2017 (last updated November 26, 2024)
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.
0
Attacker Value
Unknown
CVE-2016-7444
Disclosure Date: September 27, 2016 (last updated November 25, 2024)
The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.
0
Attacker Value
Unknown
CVE-2015-3308
Disclosure Date: September 02, 2015 (last updated October 05, 2023)
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
0