Gnu Gnutls vulnerabilities
66 known vulnerabilities affecting gnu/gnutls.
Total CVEs
66
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH24MEDIUM34
Vulnerabilities
Page 4 of 4
CVE-2013-4487P4MEDIUMCVSS 5.0v3.2.0v3.2.1+20 more2013-11-20
CVE-2013-4487 [MEDIUM] CVE-2013-4487: Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 an
Off-by-one error in the dane_raw_tlsa in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.16 and 3.2.x before 3.2.6 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries. NOTE: this issue is due to an incomplete fix for CVE-2013-4466.
nvd
CVE-2006-7239P4MEDIUMCVSS 5.0≤ 1.4.1v1.0.16+40 more2010-05-24
CVE-2006-7239 [MEDIUM] CWE-310 CVE-2006-7239: The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows
The _gnutls_x509_oid2mac_algorithm function in lib/gnutls_algorithms.c in GnuTLS before 1.4.2 allows remote attackers to cause a denial of service (crash) via a crafted X.509 certificate that uses a hash algorithm that is not supported by GnuTLS, which triggers a NULL pointer dereference.
nvd
CVE-2011-4128P4MEDIUMCVSS 4.3v2.12.0v2.12.1+20 more2011-12-08
CVE-2011-4128 [MEDIUM] CWE-119 CVE-2011-4128: Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x bef
Buffer overflow in the gnutls_session_get_data function in lib/gnutls_session.c in GnuTLS 2.12.x before 2.12.14 and 3.x before 3.0.7, when used on a client that performs nonstandard session resumption, allows remote TLS servers to cause a denial of service (application crash) via a large SessionTicket.
nvd
CVE-2012-0390P4MEDIUMCVSS 4.3≤ 3.0.10v2.2.4+54 more2012-01-06
CVE-2012-0390 [MEDIUM] CVE-2012-0390: The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if th
The DTLS implementation in GnuTLS 3.0.10 and earlier executes certain error-handling code only if there is a specific relationship between a padding length and the ciphertext size, which makes it easier for remote attackers to recover partial plaintext via a timing side-channel attack, a related issue to CVE-2011-4108.
nvd
CVE-2005-1431P4MEDIUMCVSS 5.0v1.0.18v1.0.19+8 more2005-05-03
CVE-2005-1431 [MEDIUM] CVE-2005-1431: The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers
The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c.
nvd
CVE-2014-8155P4MEDIUMCVSS 4.3≤ 2.9.92015-08-14
CVE-2014-8155 [MEDIUM] CWE-17 CVE-2014-8155: GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which a
GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate that is (1) not yet valid or (2) no longer valid.
nvd
← Previous4 / 4