Show filters
68 Total Results
Displaying 21-30 of 68
Sort by:
Attacker Value
Unknown

CVE-2009-5144

Disclosure Date: February 03, 2018 (last updated November 26, 2024)
mod-gnutls does not validate client certificates when "GnuTLSClientVerify require" is set in a directory context, which allows remote attackers to spoof clients via a crafted certificate.
0
Attacker Value
Unknown

CVE-2016-4456

Disclosure Date: August 08, 2017 (last updated November 26, 2024)
The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem.
Attacker Value
Unknown

CVE-2017-7507

Disclosure Date: June 16, 2017 (last updated November 26, 2024)
GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server application.
0
Attacker Value
Unknown

CVE-2017-7869

Disclosure Date: April 14, 2017 (last updated November 26, 2024)
GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function in opencdk/read-packet.c. This issue (which is a subset of the vendor's GNUTLS-SA-2017-3 report) is fixed in 3.5.10.
0
Attacker Value
Unknown

CVE-2017-5337

Disclosure Date: March 24, 2017 (last updated November 26, 2024)
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
0
Attacker Value
Unknown

CVE-2017-5336

Disclosure Date: March 24, 2017 (last updated November 26, 2024)
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
0
Attacker Value
Unknown

CVE-2017-5335

Disclosure Date: March 24, 2017 (last updated November 26, 2024)
The stream reading functions in lib/opencdk/read-packet.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to cause a denial of service (out-of-memory error and crash) via a crafted OpenPGP certificate.
0
Attacker Value
Unknown

CVE-2017-5334

Disclosure Date: March 24, 2017 (last updated November 26, 2024)
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.
0
Attacker Value
Unknown

CVE-2016-7444

Disclosure Date: September 27, 2016 (last updated November 25, 2024)
The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended certificate validation mechanism via vectors involving trailing bytes left by gnutls_malloc.
0
Attacker Value
Unknown

CVE-2015-3308

Disclosure Date: September 02, 2015 (last updated October 05, 2023)
Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution point.
0