
Cloud Vulnerability DB
A community-led vulnerabilities database
cryptoki treated the CKA_ALLOWED_MECHANISMS ulValueLen byte count as a
CK_MECHANISM_TYPE element count. A valid nonempty attribute returned through
the safe Session::get_attributes API could cause construction of an
out-of-bounds slice and undefined behavior.
Possible consequences include a process crash or denial of service and
potential disclosure of adjacent heap words. Upgrade to the fixed patch release
for the cryptoki 0.10, 0.11, or 0.12 line.
Source: NVD
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."