Vulnerabilidades en gnutls
5 resultadosAnálisis Vexday
O GnuTLS apresenta 2 vulnerabilidades catalogadas na base do Vexday, nenhuma delas sob ataque ativo no momento. Não há críticas de severidade alta registradas, e nenhuma foi divulgada recentemente, indicando um perfil de risco estável. A fraqueza dominante é use-after-free (CWE-416), típica de erros de gerenciamento de memória que demandam validação em profundidade durante auditorias de código.
CVE-2019-3829MEDIUMA vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verEPSS 59.0%CVE-2017-7507—GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contEPSS 3.4%CVE-2019-3836MEDIUMIt was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later whEPSS 3.4%CVE-2015-0294—GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate.EPSS 1.6%CVE-2025-13151HIGHCVE-2025-13151EPSS 1.1%