Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specification allows certain fields to be NULL, but OpenSSL does not correctly check for this case. This can lead to a NULL pointer dereference that results in OpenSSL crashing. If an application processes PKCS12 files from an untrusted source using the OpenSSL APIs then that application will be vulnerable to this issue. OpenSSL APIs that are vulnerable to this are: PKCS12_parse(), PKCS12_unpack_p7data(), PKCS12_unpack_p7encdata(), PKCS12_unpack_authsafes() and PKCS12_newpass(). We have also fixed a similar issue in SMIME_write_PKCS7(). However since this function is related to writing data we do not consider it security significant. The FIPS modules in 3.2, 3.1 and 3.0 are not affected by this issue. Join the discussion | CVE Database V5 | 08/25/2026, 00:00:00 UTC Added: 05/29/2025, 15:29:19 UTC |
This update includes the following RPMs: openssl: * openssl-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-config-fips-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-devel-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-devel-engine-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-fips-provider-upstream-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-libs-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-perl-3.5.6-0.5.hum1 (aarch64, x86_64) * openssl-3.5.6-0.5.hum1.src (src) Security Fix(es): openssl: * CVE-2026-14456 Join the discussion | GCVE Database | 08/18/2026, 10:51:22 UTC Added: 08/13/2026, 17:48:02 UTC |
0 OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system. Join the discussion | CVE Database V5 | 06/16/2025, 00:00:00 UTC Added: 06/16/2025, 22:04:29 UTC |
0 iPerf3 before 3.17, when used with OpenSSL before 3.2.0 as a server with RSA authentication, allows a timing side channel in RSA decryption operations. This side channel could be sufficient for an attacker to recover credential plaintext. It requires the attacker to send a large number of messages for decryption, as described in "Everlasting ROBOT: the Marvin Attack" by Hubert Kario. Join the discussion | CVE Database V5 | 05/13/2024, 00:00:00 UTC Added: 11/03/2025, 21:40:24 UTC |
Showing 1 to 4 of 4 results