Known Vulnerabilities for Libressl by Openbsd
Listed below are 9 of the newest known vulnerabilities associated with "Libressl" by "Openbsd".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-41581 | x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buffer ov... | 5.5 - MEDIUM | 2021-09-24 | 2021-09-29 |
| CVE-2019-25049 | LibreSSL 2.9.1 through 3.2.1 has an out-of-bounds read in asn1_item_print_ctx (called from asn1_template_print_ctx). | 7.1 - HIGH | 2021-07-01 | 2021-07-08 |
| CVE-2019-25048 | LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_item_... | 7.1 - HIGH | 2021-07-01 | 2021-07-08 |
| CVE-2018-12434 | LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the R... | 4.7 - MEDIUM | 2018-06-15 | 2018-08-06 |
| CVE-2018-8970 | The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a cert... | 7.4 - HIGH | 2018-03-24 | 2018-04-24 |
| CVE-2017-8301 | LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a ver... | 5.3 - MEDIUM | 2017-04-27 | 2019-10-03 |
| CVE-2015-5334 | Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (p... | 9.8 - CRITICAL | 2020-01-23 | 2020-01-30 |
| CVE-2015-5333 | Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory... | 7.5 - HIGH | 2020-01-23 | 2020-01-29 |
| CVE-2014-9424 | Double free vulnerability in the ssl_parse_clienthello_use_srtp_ext function in d1_srtp.c in LibreSSL before 2.1.2 allows rem... | 7.5 - HIGH | 2014-12-29 | 2014-12-30 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openbsd | Libressl | 2.9.2 | All | All | All |
| Application | Openbsd | Libressl | 2.9.1 | All | All | All |
| Application | Openbsd | Libressl | 2.9.0 | All | All | All |
| Application | Openbsd | Libressl | 2.8.3 | All | All | All |
| Application | Openbsd | Libressl | 2.8.2 | All | All | All |
| Application | Openbsd | Libressl | 2.8.1 | All | All | All |
| Application | Openbsd | Libressl | 2.8.0 | All | All | All |
| Application | Openbsd | Libressl | 2.7.5 | All | All | All |
| Application | Openbsd | Libressl | 2.7.4 | All | All | All |
| Application | Openbsd | Libressl | 2.7.3 | All | All | All |
| Application | Openbsd | Libressl | 2.7.2 | All | All | All |
| Application | Openbsd | Libressl | 2.7.1 | All | All | All |
| Application | Openbsd | Libressl | 2.7.0 | All | All | All |
| Application | Openbsd | Libressl | 2.6.5 | All | All | All |
| Application | Openbsd | Libressl | 2.6.4 | All | All | All |
| Application | Openbsd | Libressl | 2.6.3 | All | All | All |
| Application | Openbsd | Libressl | 2.6.2 | All | All | All |
| Application | Openbsd | Libressl | 2.6.1 | All | All | All |
| Application | Openbsd | Libressl | 2.6.0 | All | All | All |
| Application | Openbsd | Libressl | 2.5.5 | All | All | All |