← Back

Sfackler

sfackler

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Openssl
openssl

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sfackler
1Openssl
Jul 29, 2026
Jul 17, 2026
5.1 MEDIUM· v4
7.1 HIGH· v3
N/A· v2
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES k...Show more
rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding ciphers EVP_aes_{128,192,256}_wrap_pad. For a non-multiple-of-8 input, OpenSSL writes up to 7 bytes past the end of the caller's buffer or Vec, producing attacker-controllable heap corruption when the plaintext length is attacker-influenced. This issue is fixed in version 0.10.80.Show less
1Sfackler
1Openssl
Jun 17, 2026
Jul 28, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The openssl crate before 0.10.55 for Rust allows an out-of-bounds read via an empty string to X509VerifyParamRef::set_host.