Search CVE reports


Toggle filters

21 – 30 of 74 results


CVE-2024-23170

Medium priority
Vulnerable

An issue was discovered in Mbed TLS 2.x before 2.28.7 and 3.x before 3.5.2. There was a timing side channel in RSA private operations. This side channel could be sufficient for a local attacker to recover the plaintext. It...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2024-23744

Medium priority
Ignored

An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends a TLS 1.3 ClientHello without extensions.

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-52353

Medium priority
Ignored

An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum negotiable TLS version is mishandled. For example, if the last connection negotiated TLS 1.2, then 1.2 becomes the new maximum.

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-45199

Medium priority
Ignored

Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Not affected Not affected
Show less packages

CVE-2023-43615

Medium priority
Vulnerable

Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2021-36647

Medium priority
Vulnerable

Use of a Broken or Risky Cryptographic Algorithm in the function mbedtls_mpi_exp_mod() in lignum.c in Mbed TLS Mbed TLS all versions before 3.0.0, 2.27.0 or 2.16.11 allows attackers with access to precise enough timing and memory...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Vulnerable Vulnerable
Show less packages

CVE-2022-46393

Medium priority
Vulnerable

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2022-46392

Medium priority
Vulnerable

An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Vulnerable Vulnerable Vulnerable
Show less packages

CVE-2022-35409

Medium priority
Vulnerable

An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up...

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Vulnerable Not affected Not affected
Show less packages

CVE-2021-43666

Medium priority
Vulnerable

A Denial of Service vulnerability exists in mbed TLS 3.0.0 and earlier in the mbedtls_pkcs12_derivation function when an input password's length is 0.

1 affected package

mbedtls

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mbedtls Not affected Not affected Vulnerable Vulnerable
Show less packages