Debian Libcoap2 vulnerabilities
12 known vulnerabilities affecting debian/libcoap2.
Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM6LOW2
Vulnerabilities
Page 1 of 1
CVE-2024-0962P3LOWCVSS 6.3fixed in libcoap3 4.3.5-1 (forky)2024
CVE-2024-0962 [MEDIUM] CVE-2024-0962: libcoap2 - A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. ...
A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function get_split_entry of the file src/coap_oscore.c of the component Configuration File Handler. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It
debian
CVE-2025-65493P3HIGHCVSS 7.5fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65493 [HIGH] CVE-2025-65493: libcoap2 - NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remo...
NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS/TLS connection that triggers BIO_get_data() to return NULL.
Scope: local
bullseye: open
debian
CVE-2025-65494P3HIGHCVSS 7.5fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65494 [HIGH] CVE-2025-65494: libcoap2 - NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in O...
NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certificate that causes sk_GENERAL_NAME_value() to return NULL.
Scope: local
bullseye: open
debian
CVE-2024-31031P3LOWCVSS 7.5fixed in libcoap3 4.3.5-1 (forky)2024
CVE-2024-31031 [HIGH] CVE-2024-31031: libcoap2 - An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined be...
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
Scope: local
bullseye: resolved
debian
CVE-2024-46304P3HIGHCVSS 7.5fixed in libcoap3 4.3.5-1 (forky)2024
CVE-2024-46304 [HIGH] CVE-2024-46304: libcoap2 - A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attac...
A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c.
Scope: local
bullseye: open
debian
CVE-2025-65495P4HIGHCVSS 7.5fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65495 [HIGH] CVE-2025-65495: libcoap2 - Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM...
Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate that causes i2d_X509() to return -1 and be misused as a malloc() size parameter.
Scope: local
bullseye: open
debian
CVE-2025-65498P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65498 [MEDIUM] CVE-2025-65498: libcoap2 - NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in...
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
Scope: local
bullseye: open
debian
CVE-2025-65496P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65496 [MEDIUM] CVE-2025-65496: libcoap2 - NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in...
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
Scope: local
bullseye: open
debian
CVE-2025-65497P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65497 [MEDIUM] CVE-2025-65497: libcoap2 - NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in...
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
Scope: local
bullseye: open
debian
CVE-2025-65500P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65500 [MEDIUM] CVE-2025-65500: libcoap2 - NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in...
NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL.
Scope: local
bullseye: open
debian
CVE-2025-65501P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65501 [MEDIUM] CVE-2025-65501: libcoap2 - Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allo...
Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSL_get_app_data() returns NULL.
Scope: local
bullseye: open
debian
CVE-2025-65499P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65499 [MEDIUM] CVE-2025-65499: libcoap2 - Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoa...
Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_ex_data_X509_STORE_CTX_idx() to return -1.
Scope: local
bullseye: open
debian