CVE-2023-39914
NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.24%
- CWE
- CWE-232, CWE-240
- Published
- 2023-09-13
- Last modified
- 2026-03-13
Affected products
- NLnet Labs bcder
- NLnet Labs bcder
Weakness type
Related vulnerabilities
- CVE-2026-21689 — iccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp
- CVE-2025-20314 — A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15...
- CVE-2025-40775 — DNS message with invalid TSIG causes an assertion failure
- CVE-2025-20192 — A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE...
- CVE-2023-39915 — Crashes on parsing certain invalid RPKI objects
- CVE-2023-36848 — Junos OS: MX Series: The FPC will crash on receiving a malformed CFM packet
- CVE-2023-2968 — Undefined variable usage in npm package "proxy" leads to remote denial of service
- CVE-2022-22213 — Junos OS and Junos OS Evolved: Denial of Service (DoS) vulnerability in RPD upon receipt of specific BGP update