Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Moderate

OpenSSL TLS Server Crash (NULL pointer dereference) — CVE-2021-3449

Disclosure Date: March 25, 2021 (last updated February 22, 2025)
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a crash and a denial of service attack. A server is only vulnerable if it has TLSv1.2 and renegotiation enabled (which is the default configuration). OpenSSL TLS clients are not impacted by this issue. All OpenSSL 1.1.1 versions are affected by this issue. Users of these versions should upgrade to OpenSSL 1.1.1k. OpenSSL 1.0.2 is not impacted by this issue. Fixed in OpenSSL 1.1.1k (Affected 1.1.1-1.1.1j).
Attacker Value
Unknown

CVE-2021-30192

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
Attacker Value
Unknown

CVE-2021-30191

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
Attacker Value
Unknown

CVE-2021-30193

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
Attacker Value
Unknown

CVE-2021-30194

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
Attacker Value
Unknown

CVE-2021-30189

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
Attacker Value
Unknown

CVE-2021-30190

Disclosure Date: May 25, 2021 (last updated February 22, 2025)
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
Attacker Value
Unknown

CVE-2018-3639

Disclosure Date: May 22, 2018 (last updated November 26, 2024)
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.