Skip to main content

Vendor archive

yubico CVEs

Beta · best-effort

25 CVEs tagged to vendor yubico1 Critical, 12 High, 12 Medium, 0 Low, 0 Unrated.

CVE-2023-39908

Published Aug 14, 2023

The PKCS11 module of the YubiHSM 2 SDK through 2023.01 does not properly validate the length of specific read operations on object metadata. This may lead to disclosure of uniniti…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-24584

Published May 11, 2022

Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP supposedly creates hardware bound s…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-3298

Published Mar 30, 2022

Yubico ykneo-openpgp before 1.0.10 has a typo in which an invalid PIN can be used. When first powered up, a signature will be issued even though the PIN has not been validated.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43399

Published Dec 8, 2021

The Yubico YubiHSM YubiHSM2 library 2021.08, included in the yubihsm-shell project, does not properly validate the length of some operations including SSH signing requests, and so…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-31924

Published May 26, 2021

Yubico pam-u2f before 1.1.1 has a logic issue that, depending on the pam-u2f configuration and the application used, could lead to a local PIN bypass. This issue does not allow us…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32489

Published May 10, 2021

An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenti…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27217

Published Mar 4, 2021

An issue was discovered in the _send_secure_msg() function of Yubico yubihsm-shell through 2.0.3. The function does not correctly validate the embedded length field of an authenti…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12210

Published Jun 4, 2019

In Yubico pam-u2f 1.0.7, when configured with debug and a custom debug log file is set using debug_file, that file descriptor is not closed when a new process is spawned. This lea…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12209

Published Jun 4, 2019

Yubico pam-u2f 1.0.7 attempts parsing of the configured authfile (default $HOME/.config/Yubico/u2f_keys) as root (unless openasuser was enabled), and does not properly verify that…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20340

Published Mar 21, 2019

Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-9578

Published Mar 5, 2019

In devs.c in Yubico libu2f-host before 1.1.8, the response to init is misparsed, leaking uninitialized stack memory back to the device.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-9275

Published Apr 4, 2018

In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1