← Back

Wolfssl

wolfssl

149 CVEs • 3 products

Products (3)

Click to collapse
Toggle
Wolfssl
wolfssl
Wolfmqtt
wolfmqtt
Yassl
yassl

CVEs (149)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wolfssl
1Wolfssl
May 13, 2026
May 9, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
wolfSSL before 3.11.0 does not prevent wc_DhAgree from accepting a malformed DH key.
1Wolfssl
1Wolfssl
May 13, 2026
May 9, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
wolfSSL before 3.10.2 has an out-of-bounds memory access with loading crafted DH parameters, aka a buffer overflow triggered by a malformed temporary DH file.
1Wolfssl
1Wolfssl
May 13, 2026
Feb 24, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In versions of wolfSSL before 3.10.2 the function fp_mul_comba makes it easier to extract RSA key information for a malicious user who has access to view cache on a machine.
4Debian
MariadbOracle+1 more
4Debian Linux
MariadbMysql+1 more
May 6, 2026
Dec 13, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The C software implementation of AES Encryption and Decryption in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover AES keys by leveraging cache-bank timing differences.
1Wolfssl
1Wolfssl
May 6, 2026
Dec 13, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The C software implementation of RSA in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
1Wolfssl
1Wolfssl
May 6, 2026
Dec 13, 2016
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The C software implementation of ECC in wolfSSL (formerly CyaSSL) before 3.9.10 makes it easier for local users to discover RSA keys by leveraging cache-bank hit differences.
3Mariadb
OpensuseWolfssl
4Leap
MariadbOpensuse+1 more
May 6, 2026
Jan 22, 2016
N/A· v4
5.9 MEDIUM· v3
2.6 LOW· v2
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which...Show more
wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attackers to obtain private RSA keys by capturing TLS handshakes, aka a Lenstra attack.Show less
1Wolfssl
1Wolfssl
May 6, 2026
Jan 22, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.
5Canonical
DebianMariadb+2 more
5Debian Linux
MariadbMysql+2 more
Apr 23, 2026
Dec 30, 2009
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through...Show more
Multiple stack-based buffer overflows in the CertDecoder::GetName function in src/asn.cpp in TaoCrypt in yaSSL before 1.9.9, as used in mysqld in MySQL 5.0.x before 5.0.90, MySQL 5.1.x before 5.1.43, MySQL 5.5.x through 5.5.0-m2, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and daemon crash) by establishing an SSL connection and sending an X.509 client certificate with a crafted name field, as demonstrated by mysql_overflow1.py and the vd_mysql5 module in VulnDisco Pack Professional 8.11. NOTE: this was originally reported for MySQL 5.0.51a.Show less