Vulnerabilities in wolfssl
94 resultsVexday analysis
WolfSSL apresenta um perfil de risco mínimo com apenas 1 CVE catalogado na base, sem registros de exploração ativa ou vulnerabilidades críticas. A fraqueza identificada (CWE-122 - buffer overflow) é de natureza clássica, porém o risco permanece contido pela baixa exposição histórica do fornecedor e ausência de atividade recente de ataque.
CVE-2017-13099HIGHwolfSSL Bleichenbacher/ROBOTEPSS 24.9%CVE-2017-2800HIGHA specially crafted x509 certificate can cause a single out of bounds byte overwrite in wolfSSL through 3.10.2 resulting in potential certifEPSS 8.5%CVE-2024-0901HIGHSEGV and out of bounds memory read from malicious packetEPSS 0.7%CVE-2023-3724CRITICALTLS 1.3 client issue handling malicious server when not including a KSE and PSK extensionEPSS 0.7%CVE-2023-6936MEDIUM Heap-buffer over-read with WOLFSSL_CALLBACKSEPSS 0.6%CVE-2024-1545MEDIUMFault Injection of RSA encryption in WolfCryptEPSS 0.6%CVE-2024-5991CRITICALBuffer overread in domain name matchingEPSS 0.6%CVE-2023-6935MEDIUMMarvin Attack vulnerability in SP Math All RSAEPSS 0.5%CVE-2026-6094MEDIUMHeap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedDataEPSS 0.5%CVE-2023-6937MEDIUMImproper (D)TLS key boundary enforcementEPSS 0.5%CVE-2026-6679HIGHDTLS 1.3 ACK serialization heap buffer overflow via integer truncationEPSS 0.5%CVE-2026-7531LOWUse-after-free in PQC hybrid key-share handlingEPSS 0.5%CVE-2026-3548HIGHBuffer overflow in CRL number parsing in wolfSSLEPSS 0.5%CVE-2024-5814MEDIUMUnverifed Ciphersuite used on a client-side TLS1.3 DowngradeEPSS 0.5%CVE-2024-2881MEDIUMFault Injection of EdDSA signature in WolfCryptEPSS 0.5%CVE-2026-10512LOWX25519 x86_64 assembly final reduction leaves non-canonical field elementEPSS 0.5%CVE-2026-5194CRITICALwolfSSL ECDSA Certificate VerificationEPSS 0.4%CVE-2026-5264HIGHDTLS 1.3 ACK heap buffer overflowEPSS 0.4%CVE-2026-55958HIGHRenesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessageEPSS 0.4%CVE-2025-11625CRITICALHost verification bypass and credential leakEPSS 0.4%