Search CVE reports
111 – 120 of 29671 results
PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify path compared the locally computed HMAC against the...
1 affected package
wolfssl
| Package | 26.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.
1 affected package
wolfssl
| Package | 26.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.
1 affected package
wolfssl
| Package | 26.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The post-handshake-auth exemption that allows an...
1 affected package
wolfssl
| Package | 26.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability
1 affected package
vtk-dicom
| Package | 26.04 LTS |
|---|---|
| vtk-dicom | Needs evaluation |
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security...
1 affected package
chromium-browser
| Package | 26.04 LTS |
|---|---|
| chromium-browser | Not affected |
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)
1 affected package
chromium-browser
| Package | 26.04 LTS |
|---|---|
| chromium-browser | Not affected |
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
1 affected package
chromium-browser
| Package | 26.04 LTS |
|---|---|
| chromium-browser | Not affected |
Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for ticket-based resumption. A cached session could be resumed under a different SNI/ALPN than originally...
1 affected package
wolfssl
| Package | 26.04 LTS |
|---|---|
| wolfssl | Needs evaluation |
OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status allows a same-issuer SingleResponse whose serial is a prefix of the target serial to be reported as the revocation status of a different certificate. The...
1 affected package
wolfssl
| Package | 26.04 LTS |
|---|---|
| wolfssl | Needs evaluation |