Výsledky hledání

výrobce: OpenSSL× v celém archivu zrušit filtry

12 karet z 13 položek CZ · EN/orig

1

SPOJENO PŘES CVE K000162604: NGINX ngx_http_v3_module vulnerability CVE-2026-90439

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 6.5, CVEs: CVE-2026-90439, Summary: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions 3.5.0 and earlier under certain configurations, a limited heap buffer overflow could happen while processing a Transport Layer Security (TLS) handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This…

EPSS 0.00 CVSS 6.5 CVE-2026-90439 NGINX OpenSSL F5 FI FR

tg: zranitelnost

· NCSC-FI · K000162604: NGINX ngx_http_v3_module vulnerability CVE-2026-90439 · CERT-FR – avis · Vulnérabilité dans F5 NGINX (16 septembre 2026)

1

Multiple Vulnerabilities in OpenSSL

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.8, CVEs: CVE-2026-63076, CVE-2026-63075, CVE-2026-63074, CVE-2026-63072, CVE-2026-54874, CVE-2026-18798, CVE-2026-14457, CVE-2026-75803, Summary: CVE-2026-63076 7.5 Invalid Pointer Dereference in CMP Server via Crafted protectionAlg CVE-2026-63075 7.5 QUIC ACK-only Packet Retention Can Cause Memory Exhaustion CVE-2026-63074 5.9 CMP Indefinite Cache Growth of ExtraCerts CVE-2026-63072 7.5 Heap Buffer…

EPSS 0.01 CVSS 7.8 CVE-2026-14457 CVE-2026-18798 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 OpenSSL FI

· NCSC-FI · Multiple Vulnerabilities in OpenSSL

1

Multiples vulnérabilités dans OpenSSL (26 août 2026)

De multiples vulnérabilités ont été découvertes dans OpenSSL. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.

EPSS 0.01 CVE-2026-14457 CVE-2026-18798 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803 OpenSSL FR

· CERT-FR – avis · Multiples vulnérabilités dans OpenSSL (26 août 2026)

2

OpenSSL security advisory (AV26-846)

Serial Number: AV26-846Date: August 25, 2026 As of August 25, 2026, OpenSSL is affected by vulnerabilities in the following product: OpenSSL Prior to 1.0.2zr Prior to 1.1.1zi Prior to 3.0.22 Prior to 3.4.7 Prior to 3.5.8 Prior to 3.6.4 Prior to 4.0.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Vulnerabilities | OpenSSL Library

OpenSSL CA

· Cyber Centre Kanada · OpenSSL security advisory (AV26-846)

1

SPOJENO PŘES CVE Risolta vulnerabilità in OpenSSL

Rilasciato aggiornamento di sicurezza per una nuova vulnerabilità, con gravità “alta“, che interessa OpenSSL, nota libreria per l’implementazione degli standard crittografici e i protocolli TLS/SSL. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato di compromettere la disponibilità del servizio sui sistemi interessati.

EPSS 0.01 CVE-2026-14456 OpenSSL IT FR

· CSIRT Itálie (ACN) · Risolta vulnerabilità in OpenSSL · CERT-FR – avis · Vulnérabilité dans OpenSSL (14 août 2026)

2

ZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenSSL. User interaction is required to exploit this vulnerability in that the target must make a request to a malicious server. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-35188.

EPSS 0.00 CVSS 7.5 CVE-2026-35188 OpenSSL US

· Zero Day Initiative · ZDI-26-425: OpenSSL OCSP Stapling Verification Double Free Remote Code Execution Vulnerability

ZDI-26-426: OpenSSL X.509 Email Validation Out-Of-Bounds Read Information Disclosure Vulnerability

This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenSSL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2026-42771.

EPSS 0.00 CVSS 6.5 CVE-2026-42771 OpenSSL US

· Zero Day Initiative · ZDI-26-426: OpenSSL X.509 Email Validation Out-Of-Bounds Read Information Disclosure Vulnerability

1

CVE-2017-3736 There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.

Information published.

EPSS 0.10 CVE-2017-3736 OpenSSL US

· Microsoft Security · CVE-2017-3736 There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH are considered just feasible (although very difficult) because most of the work necessary to deduce information about a private key may be performed offline. The amount of resources required for such an attack would be very significant and likely only accessible to a limited number of attackers. An attacker would additionally need online access to an unpatched system using the target private key in a scenario with persistent DH parameters and a private key that is shared between multiple clients. This only affects processors that support the BMI1, BMI2 and ADX extensions like Intel Broadwell (5th generation) and later or AMD Ryzen.

1

1

Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL

[VDE-2026-023] Attacks are possible when installing key files and digitally signed objects. These attacks can only be carried out if these files are uploaded and installed by a logged-in user with high privileges.

EPSS 0.48 CVE-2025-15467 CVE-2025-69419 Phoenix Contact OpenSSL DE

tg: zranitelnost tp: průmyslové systémy

· CERT@VDE · Phoenix Contact: Several products are affected by vulnerabilities found in OpenSSL

1