Xyssl is a narrowly scoped cryptographic library project with a compact product footprint and embedded presence in downstream applications and systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xyssl over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-7128HIGH The ssl_parse_client_key_exchange function in XySSL before 0.9 does not protect against certain Bleichenbacher attacks using chosen ciphertext, which allows remote attackers to rec | Aug 31, 2009 | 7.5 | 19 | NO | NO |
CVE-2008-7129MEDIUM XySSL before 0.9 allows remote attackers to cause a denial of service (infinite loop) via an X.509 certificate that does not pass the RSA signature check during verification. | Aug 31, 2009 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xyssl.
Media articles that mention a CVE ID that affects a product developed by Xyssl — matched by CVE ID, not by vendor name.