cbcvebase.

Debian Libcoap2 vulnerabilities

12 known vulnerabilities affecting debian/libcoap2.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM6LOW2

Vulnerabilities

Page 1 of 1
CVE-2024-0962P3LOWCVSS 6.3fixed in libcoap3 4.3.5-1 (forky)2024
CVE-2024-0962 [MEDIUM] CVE-2024-0962: libcoap2 - A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. ... A vulnerability was found in obgm libcoap 4.3.4. It has been rated as critical. Affected by this issue is the function get_split_entry of the file src/coap_oscore.c of the component Configuration File Handler. The manipulation leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It
debian
CVE-2025-65493P3HIGHCVSS 7.5fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65493 [HIGH] CVE-2025-65493: libcoap2 - NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remo... NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS/TLS connection that triggers BIO_get_data() to return NULL. Scope: local bullseye: open
debian
CVE-2025-65494P3HIGHCVSS 7.5fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65494 [HIGH] CVE-2025-65494: libcoap2 - NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in O... NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted X.509 certificate that causes sk_GENERAL_NAME_value() to return NULL. Scope: local bullseye: open
debian
CVE-2024-31031P3LOWCVSS 7.5fixed in libcoap3 4.3.5-1 (forky)2024
CVE-2024-31031 [HIGH] CVE-2024-31031: libcoap2 - An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined be... An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow. Scope: local bullseye: resolved
debian
CVE-2024-46304P3HIGHCVSS 7.5fixed in libcoap3 4.3.5-1 (forky)2024
CVE-2024-46304 [HIGH] CVE-2024-46304: libcoap2 - A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attac... A NULL pointer dereference in libcoap v4.3.5-rc2 and below allows a remote attacker to cause a denial of service via the coap_handle_request_put_block function in src/coap_block.c. Scope: local bullseye: open
debian
CVE-2025-65495P4HIGHCVSS 7.5fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65495 [HIGH] CVE-2025-65495: libcoap2 - Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM... Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted TLS certificate that causes i2d_X509() to return -1 and be misused as a malloc() size parameter. Scope: local bullseye: open
debian
CVE-2025-65498P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65498 [MEDIUM] CVE-2025-65498: libcoap2 - NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in... NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL. Scope: local bullseye: open
debian
CVE-2025-65496P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65496 [MEDIUM] CVE-2025-65496: libcoap2 - NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in... NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL. Scope: local bullseye: open
debian
CVE-2025-65497P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65497 [MEDIUM] CVE-2025-65497: libcoap2 - NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in... NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL. Scope: local bullseye: open
debian
CVE-2025-65500P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65500 [MEDIUM] CVE-2025-65500: libcoap2 - NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in... NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_SSL_CTX() to return NULL. Scope: local bullseye: open
debian
CVE-2025-65501P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65501 [MEDIUM] CVE-2025-65501: libcoap2 - Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allo... Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a DTLS handshake where SSL_get_app_data() returns NULL. Scope: local bullseye: open
debian
CVE-2025-65499P4MEDIUMCVSS 4.3fixed in libcoap3 4.3.5-2 (forky)2025
CVE-2025-65499 [MEDIUM] CVE-2025-65499: libcoap2 - Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoa... Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of service via a crafted DTLS handshake that triggers SSL_get_ex_data_X509_STORE_CTX_idx() to return -1. Scope: local bullseye: open
debian
Debian Libcoap2 vulnerabilities | cvebase