OpenSSL是OpenSSL团队的一个开源的能够实现安全套接层(SSLv2/v3)和安全传输层(TLSv1)协议的通用加密库。该产品支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。 OpenSSL 3.6版本、3.5版本、3.4版本、3.3版本、3.0版本和1.1.1版本存在安全漏洞,该漏洞源于PKCS12_get_friendlyname函数处理特制PKCS#12文件不当,可能导致越界写入和内存损坏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-22795 | Missing ASN1_TYPE validation in PKCS#12 parsing | |
| CVE-2026-22796 | ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() function | |
| CVE-2025-15467 | Stack buffer overflow in CMS (Auth)EnvelopedData parsing | |
| CVE-2025-15469 | 'openssl dgst' one-shot codepath silently truncates inputs >16MB | |
| CVE-2025-15468 | NULL dereference in SSL_CIPHER_find() function on unknown cipher ID | |
| CVE-2025-66199 | TLS 1.3 CompressedCertificate excessive memory allocation | |
| CVE-2025-68160 | Heap out-of-bounds write in BIO_f_linebuffer on short writes | |
| CVE-2025-11187 | Improper validation of PBMAC1 parameters in PKCS#12 MAC verification | |
| CVE-2025-69421 | NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex function | |
| CVE-2025-69420 | Missing ASN1_TYPE validation in TS_RESP_verify_response() function | |
| CVE-2025-69418 | Unauthenticated/unencrypted trailing bytes with low-level OCB function calls |
No comments yet