Filtered by vendor Xyssl
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2008-7129 | 1 Xyssl | 1 Xyssl | 2024-11-21 | 5.0 MEDIUM | N/A |
XySSL before 0.9 allows remote attackers to cause a denial of service (infinite loop) via an X.509 certificate that does not pass the RSA signature check during verification. | |||||
CVE-2008-7128 | 1 Xyssl | 1 Xyssl | 2024-11-21 | 7.5 HIGH | N/A |
The ssl_parse_client_key_exchange function in XySSL before 0.9 does not protect against certain Bleichenbacher attacks using chosen ciphertext, which allows remote attackers to recover keys via unspecified vectors. |