NA - CVE-2024-1544 - Generating the ECDSA nonce k samples a random...
Generating the ECDSA nonce k samples a random number r and then truncates this randomness with a modular reduction mod n where n is the order of the elliptic curve. Meaning k = r mod n. The...
NA - CVE-2024-45037 - The AWS Cloud Development Kit (CDK) is an...
The AWS Cloud Development Kit (CDK) is an open-source framework for defining cloud infrastructure using code. Customers use it to create their own applications which are converted to AWS...
NA - CVE-2024-5288 - An issue was discovered in wolfSSL before...
An issue was discovered in wolfSSL before 5.7.0. A safe-error attack via Rowhammer, namely FAULT+PROBE, leads to ECDSA key disclosure. When WOLFSSL_CHECK_SIG_FAULTS is used in signing operations...
NA - CVE-2024-5814 - A malicious TLS1.2 server can force a TLS1.3...
A malicious TLS1.2 server can force a TLS1.3 client with downgrade capability to use a ciphersuite that it did not agree to and achieve a successful connection. This is because, aside from the...
NA - CVE-2024-5991 - In function MatchDomainName(), input param str...
In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and...
NA - CVE-2024-8213 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L,...