Asn1c Project maintains an ASN.1 compiler widely embedded in telecommunications, security, and standards-compliant protocols, a narrow but foundational role in systems handling structured data encoding. The observed vulnerability surface centers on memory-safety issues—buffer overflows, out-of-bounds writes, and NULL-pointer dereferences—characteristic of C-based parsers processing untrusted or malformed ASN.1 input. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Asn1c Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-23911MEDIUM An issue was discovered in asn1c through v0.9.28. A NULL pointer dereference exists in the function _default_error_logger() located in asn1fix.c. It allows an attacker to cause Den | Jul 18, 2023 | 5.5 | 18 | NO | NO |
CVE-2020-23910MEDIUM Stack-based buffer overflow vulnerability in asn1c through v0.9.28 via function genhash_get in genhash.c. | Jul 18, 2023 | 5.5 | 18 | NO | NO |
CVE-2017-12966MEDIUM The asn1f_lookup_symbol_impl function in asn1fix_retrieve.c in libasn1fix.a in asn1c 0.9.28 allows remote attackers to cause a denial of service (segmentation fault) via a crafted | Aug 20, 2017 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Asn1c Project.
Media articles that mention a CVE ID that affects a product developed by Asn1c Project — matched by CVE ID, not by vendor name.