Libressl

OpenBSD · 12 CVEs

CVE-2023-35784
CRITICAL

A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004,…

Jun 16, 2023

CVE-2021-46880
CRITICAL

x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an…

Apr 14, 2023

CVE-2022-48437
MEDIUM

An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_veri…

Apr 12, 2023

CVE-2021-41581
MEDIUM

x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buf…

Sep 24, 2021

CVE-2019-25049
HIGH

LibreSSL 2.9.1 through 3.2.1 has an out-of-bounds read in asn1_item_print_ctx (called from asn1_template_print_ctx).

Jul 1, 2021

CVE-2019-25048
HIGH

LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1…

Jul 1, 2021

CVE-2015-5333
HIGH

Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (…

Jan 23, 2020

CVE-2015-5334
CRITICAL

Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of serv…

Jan 23, 2020

CVE-2018-12434
MEDIUM

LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka…

Jun 15, 2018

CVE-2018-8970
HIGH

The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support…

Mar 24, 2018

CVE-2017-8301
MEDIUM

LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of…

Apr 27, 2017

CVE-2014-9424
HIGH

libressl: Double-free in ssl_parse_clienthello_use_srtp_ext() function

Dec 29, 2014

Showing 1 to 12 of 12 CVEs