Gnu Gnutls vulnerabilities
66 known vulnerabilities affecting gnu/gnutls.
Total CVEs
66
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH24MEDIUM34
Vulnerabilities
Page 1 of 4
CVE-2009-3555P1CRITICALCVSS 9.8ExploitedPoC≤ 2.8.52009-11-09
CVE-2009-3555 [CRITICAL] CWE-295 CVE-2009-3555: The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Infor
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properl
nvd
CVE-2019-3829P3HIGHCVSS 7.5≥ 3.5.8, < 3.6.72019-03-27
CVE-2019-3829 [HIGH] CWE-416 CVE-2019-3829: A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double fr
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 or later is affected.
nvd
CVE-2009-1416P3HIGHCVSS 7.5PoCv2.5.0v2.6.0+5 more2009-04-30
CVE-2009-1416 [HIGH] CWE-310 CVE-2009-1416: lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structur
lib/gnutls_pk.c in libgnutls in GnuTLS 2.5.0 through 2.6.5 generates RSA keys stored in DSA structures, instead of the intended DSA keys, which might allow remote attackers to spoof signatures on certificates or have unspecified other impact by leveraging an invalid DSA key.
nvd
CVE-2017-5334P3CRITICALCVSS 9.8≤ 3.3.25v3.5.0+7 more2017-03-24
CVE-2017-5334 [CRITICAL] CWE-415 CVE-2017-5334: Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via crafted policy language information in an X.509 certificate with a Proxy Certificate Information extension.
nvd
CVE-2020-13777P3HIGHCVSS 7.4≥ 3.6.0, < 3.6.142020-06-04
CVE-2020-13777 [HIGH] CWE-327 CVE-2020-13777: GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of co
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryp
nvd
CVE-2012-1663P3HIGHCVSS 7.5PoC≤ 3.0.13v1.0.16+163 more2012-03-13
CVE-2012-1663 [HIGH] CWE-399 CVE-2012-1663: Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a de
Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted certificate list.
nvd
CVE-2017-5336P3CRITICALCVSS 9.8≤ 3.3.25v3.5.0+7 more2017-03-24
CVE-2017-5336 [CRITICAL] CWE-119 CVE-2017-5336: Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS befor
Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.
nvd
CVE-2021-20231P3CRITICALCVSS 9.8≥ 3.6.3, < 3.7.1vgnutls 3.7.12021-03-12
CVE-2021-20231 [CRITICAL] CWE-416 CVE-2021-20231: A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
nvd
CVE-2017-5337P3CRITICALCVSS 9.8≤ 3.3.25v3.5.0+7 more2017-03-24
CVE-2017-5337 [CRITICAL] CWE-119 CVE-2017-5337: Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.
Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.
nvd
CVE-2008-1948P3CRITICALCVSS 10.0v1.0.18v1.0.19+103 more2008-05-21
CVE-2008-1948 [CRITICAL] CWE-189 CVE-2008-1948: The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in
The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly calculate the number of Server Names in a TLS 1.0 Client Hello message during extension handling, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a zero v
nvd
CVE-2021-20232P3CRITICALCVSS 9.8≥ 3.6.3, < 3.7.1vgnutls 3.7.12021-03-12
CVE-2021-20232 [CRITICAL] CWE-416 CVE-2021-20232: A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
nvd
CVE-2025-32988P3HIGHCVSS 8.2fixed in 3.8.102025-07-10
CVE-2025-32988 [HIGH] CWE-415 CVE-2025-32988: A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed, GnuTLS will call asn1_delete_structure() on an ASN.1 node it does not own, leading to a double-free condition when
nvdosv
CVE-2020-11501P3HIGHCVSS 7.4≥ 3.6.3, < 3.6.132020-04-03
CVE-2020-11501 [HIGH] CWE-330 CVE-2020-11501: GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
nvd
CVE-2016-4456P3HIGHCVSS 7.5v3.4.122017-08-08
CVE-2016-4456 [HIGH] CWE-20 CVE-2016-4456: The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite a
The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem.
nvd
CVE-2024-0553P3HIGHCVSS 7.5fixed in 3.8.32024-01-16
CVE-2024-0553 [HIGH] CVE-2024-0553: A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKe
A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the RSA-PSK key exchange, potentially leading to the leakage of sensitive data. CVE-2024-05
nvd
CVE-2023-0361P3HIGHCVSS 7.4v3.6.8-11.el8_2vgnutls-3.7.62023-02-15
CVE-2023-0361 [HIGH] CWE-203 CVE-2023-0361: A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. Th
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the
nvd
CVE-2009-1415P4MEDIUMCVSS 4.3PoCfixed in 2.6.62009-04-30
CVE-2009-1415 [MEDIUM] CWE-824 CVE-2009-1415: lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatur
lib/pk-libgcrypt.c in libgnutls in GnuTLS before 2.6.6 does not properly handle invalid DSA signatures, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via a malformed DSA key that triggers a (1) free of an uninitialized pointer or (2) double free.
nvd
CVE-2014-0092P3MEDIUMCVSS 5.8≤ 3.2.11v3.2.0+33 more2014-03-07
CVE-2014-0092 [MEDIUM] CWE-310 CVE-2014-0092: lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecifi
lib/x509/verify.c in GnuTLS before 3.1.22 and 3.2.x before 3.2.12 does not properly handle unspecified errors when verifying X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers via a crafted certificate.
nvd
CVE-2024-0567P3HIGHCVSS 7.5≥ 3.7.0, < 3.8.32024-01-16
CVE-2024-0567 [HIGH] CWE-347 CVE-2024-0567: A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
nvd
CVE-2014-3466P3MEDIUMCVSS 6.8v3.3.0v3.3.1+44 more2014-06-03
CVE-2014-3466 [MEDIUM] CWE-119 CVE-2014-3466: Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25,
Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a long session id in a ServerHello message.
nvd
1 / 4Next →