Skip to main content

Vendor archive

openca CVEs

Beta · best-effort

4 CVEs tagged to vendor openca0 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2008-0556

Published Feb 19, 2008

Cross-site request forgery (CSRF) vulnerability in OpenCA PKI 0.9.2.5, and possibly earlier versions, allows remote attackers to perform unauthorized actions as authorized users v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0787

Published Oct 20, 2004

Cross-site scripting (XSS) vulnerability in the web frontend in OpenCA 0.9.1-8 and earlier, and 0.9.2 RC6 and earlier, allows remote attackers to inject arbitrary web script or HT…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0004

Published Feb 17, 2004

The libCheckSignature function in crypto-utils.lib for OpenCA 0.9.1.6 and earlier only compares the serial of the signer's certificate and the one in the database, which can cause…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-0960

Published Dec 15, 2003

OpenCA before 0.9.1.4 does not use the correct certificate in a chain to check the serial, which could cause OpenCA to accept revoked or expired certificates.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1