Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2022-3515
Disclosure Date: January 12, 2023 (last updated October 08, 2023)
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
0
Attacker Value
Unknown
CVE-2022-47629
Disclosure Date: December 20, 2022 (last updated October 08, 2023)
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
0
Attacker Value
Unknown
CVE-2016-4353
Disclosure Date: June 13, 2016 (last updated November 08, 2023)
ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.
0
Attacker Value
Unknown
CVE-2016-4579
Disclosure Date: June 13, 2016 (last updated November 08, 2023)
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
0
Attacker Value
Unknown
CVE-2016-4355
Disclosure Date: June 13, 2016 (last updated November 08, 2023)
Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
0
Attacker Value
Unknown
CVE-2016-4354
Disclosure Date: June 13, 2016 (last updated November 08, 2023)
ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
0
Attacker Value
Unknown
CVE-2016-4356
Disclosure Date: June 13, 2016 (last updated November 08, 2023)
The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.
0
Attacker Value
Unknown
CVE-2016-4574
Disclosure Date: June 13, 2016 (last updated November 08, 2023)
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-4356.
0
Attacker Value
Unknown
CVE-2014-9087
Disclosure Date: December 01, 2014 (last updated October 05, 2023)
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
0
Attacker Value
Unknown
CVE-2006-5111
Disclosure Date: October 03, 2006 (last updated October 04, 2023)
The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows attackers to cause a denial of service (application crash) via a malformed X.509 certificate in a signature.
0