The Free Software Foundation Inc maintains a narrowly scoped portfolio centered on libtasn1, a foundational ASN.1 parsing library widely embedded in cryptographic and authentication infrastructure. The vendor's vulnerability history reflects the parsing complexity inherent to standards-based data-structure handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Free Software Foundation Inc over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0401HIGH Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions. | Jul 7, 2004 | 10.0 | 25 | NO | NO |
CVE-2006-0645HIGH Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and pos | Feb 10, 2006 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Free Software Foundation Inc.
Media articles that mention a CVE ID that affects a product developed by Free Software Foundation Inc — matched by CVE ID, not by vendor name.