← Vulnerability feed

Vulnerability record · CVE-2017-2782 · published 22 June 2017

CVE-2017-2782: Matrixssl integer overflow vulnerability

MMatrixssl · Matrixssl

An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection

9.1 CVSS 3.0 Critical EPSS 1.0% · top 38.3% CWE-190 · Integer overflow
9.1CVSS 3.0 base score, v2 6.4
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An integer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a length counter to overflow, leading to a controlled out of bounds copy operation. To trigger this vulnerability, a specially crafted x509 certificate must be presented to the vulnerable client or server application when initiating secure connection

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.securityfocus.com/bid/99249 Third Party AdvisoryVDB Entry
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0278 ExploitThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/99249 Third Party AdvisoryVDB Entry
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0278 ExploitThird Party AdvisoryVDB Entry

Track CVE-2017-2782 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-43974Matrixssl integer overflow vulnerabilityMatrixSSL 4.0.4 through 4.5.1 has an integer overflow in matrixSslDecodeTls13. A remote attacker might be able to send a crafted TLS Message to cause…EPSS 1.7%9.8CVE-2019-14431Matrixssl out-of-bounds write vulnerabilityIn MatrixSSL 3.8.3 Open through 4.2.1 Open, the DTLS server mishandles incoming network messages leading to a heap-based buffer overflow of up to 256…EPSS 3.6%9.8CVE-2019-13470Matrixssl out-of-bounds read vulnerabilityMatrixSSL before 4.2.1 has an out-of-bounds read during ASN.1 handling.EPSS 1.6%9.8CVE-2019-10914Matrixssl improper certificate validation vulnerabilitypubRsaDecryptSignedElementExt in MatrixSSL 4.0.1 Open, as used in Inside Secure TLS Toolkit, has a stack-based buffer overflow during X.509 certifica…EPSS 1.4%9.8CVE-2017-2780Matrixssl out-of-bounds write vulnerabilityAn exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially …EPSS 2.3%9.8CVE-2017-2781Matrixssl out-of-bounds write vulnerabilityAn exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially …EPSS 2.3%9.8CVE-2016-6890Matrixssl memory buffer overflow vulnerabilityHeap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an X.509 cer…EPSS 6.4%7.5CVE-2023-24609Matrixssl integer overflow vulnerabilityMatrix SSL 4.x through 4.6.0 and Rambus TLS Toolkit have a length-subtraction integer overflow for Client Hello Pre-Shared Key extension parsing in t…EPSS 0.73%

Source: NIST National Vulnerability Database (record CVE-2017-2782), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.