VYPR

Matrixssl

by Matrixssl

CVEs (26)

  • CVE-2016-8671MedJan 13, 2017
    risk 0.38cvss 5.9epss 0.01

    The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6887.

  • CVE-2016-6887MedJan 13, 2017
    risk 0.38cvss 5.9epss 0.01

    The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via a CRT attack.

  • CVE-2017-1000417MedJan 22, 2018
    risk 0.35cvss 5.3epss 0.01

    MatrixSSL version 3.7.2 adopts a collision-prone OID comparison logic resulting in possible spoofing of OIDs (e.g. in ExtKeyUsage extension) on X.509 certificates.

  • CVE-2018-12439MedJun 15, 2018
    risk 0.31cvss 4.7epss 0.00

    MatrixSSL through 3.9.5 Open allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical…

  • CVE-2004-2682Dec 31, 2004
    risk 0.00cvss epss 0.01

    PeerSec MatrixSSL before 1.1 does not implement RSA blinding, which allows context-dependent attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of…

  • CVE-2004-2681Dec 31, 2004
    risk 0.00cvss epss 0.01

    PeerSec MatrixSSL before 1.1 caches session keys for an indefinitely long time, which might make it easier for remote attackers to hijack a session.

Page 2 of 2