VYPR
Vendor

Yubico

Products
49
CVEs
32
Across products
59
Status
Private

Products

49
View all 49 products →

Recent CVEs

32
View all 32 CVEs →
  • CVE-2024-31498HigApr 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Yubico ykman-gui (aka YubiKey Manager GUI) before 1.2.6 on Windows, when Edge is not used, allows privilege escalation because browser windows can open as Administrator.

  • CVE-2015-3298HigMar 30, 2022
    risk 0.57cvss 8.8epss 0.01

    Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.

  • CVE-2011-4120CriNov 26, 2019
    risk 0.57cvss 9.8epss 0.02

    Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and…

  • CVE-2020-10185HigMar 5, 2020
    risk 0.56cvss 8.6epss 0.01

    The sync endpoint in YubiKey Validation Server before 2.40 allows remote attackers to replay an OTP. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP validation service with a non-default configuration such as an open sync pool;…

  • CVE-2019-12210HigJun 4, 2019
    risk 0.53cvss 8.1epss 0.02

    In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This leads to the file descriptor being inherited into the child process; the child process can then read…

  • CVE-2018-9275HigApr 4, 2018
    risk 0.53cvss 8.2epss 0.01

    In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file…

  • CVE-2023-39908HigAug 14, 2023
    risk 0.49cvss 7.5epss 0.01

    The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uninitialized and previously used memory.

  • CVE-2021-43399HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations including SSH signing requests, and some data operations received from a YubiHSM 2 device.

  • CVE-2020-24388HigOct 19, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This…

  • CVE-2020-24387HigOct 19, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in the session array. This…

  • CVE-2020-10184HigMar 5, 2020
    risk 0.49cvss 7.5epss 0.01

    The verify endpoint in YubiKey Validation Server before 2.40 does not check the length of SQL queries, which allows remote attackers to cause a denial of service, aka SQL injection. NOTE: this issue is potentially relevant to persons outside Yubico who operate a self-hosted OTP…

  • CVE-2019-12209HigJun 4, 2019
    risk 0.49cvss 7.5epss 0.03

    Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that the path lacks symlinks pointing to other files on the system owned by root. If the debug option is…

  • CVE-2019-9578HigMar 5, 2019
    risk 0.49cvss 7.5epss 0.02

    In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.

  • CVE-2025-23013HigJan 15, 2025
    risk 0.47cvss —epss 0.00

    In Yubico pam-u2f before 1.3.1, local privilege escalation can sometimes occur. This product implements a Pluggable Authentication Module (PAM) that can be deployed to support authentication using a YubiKey or other FIDO compliant authenticators on macOS or Linux. This software…

  • CVE-2021-31924MedMay 26, 2021
    risk 0.44cvss 6.8epss 0.00

    Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow user presence (touch) or cryptographic signature verification to be bypassed, so an attacker would…

  • CVE-2018-20340MedMar 21, 2019
    risk 0.44cvss 6.8epss 0.01

    Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the…

  • CVE-2018-14779MedAug 15, 2018
    risk 0.44cvss 6.8epss 0.00

    A buffer overflow issue was discovered in the Yubico-Piv 1.5.0 smartcard driver. The file lib/ykpiv.c contains the following code in the function `ykpiv_transfer_data()`: {% highlight c %} if(*out_len + recv_len - 2 > max_out) { fprintf(stderr, "Output buffer to small, wanted to…

  • CVE-2026-46419HigMay 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2.8.2 incorrectly checks a function's return value in the second factor flow, leading to impersonation.

  • CVE-2022-24584MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP supposedly creates hardware bound second factor credentials. When a user reprograms the OTP functionality by "writing" it on a token…

  • CVE-2021-28484HigApr 14, 2021
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in the /api/connector endpoint handler in Yubico yubihsm-connector before 3.0.1 (in YubiHSM SDK before 2021.04). The handler did not validate the length of the request, which can lead to a state where yubihsm-connector becomes stuck in a loop waiting for…