The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.
x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buffer over-read. When the input exceeds DOMAIN_PART_MAX_LEN, the buffer lacks '\0' termination.
Base Score: 4.3
Impact Score: 2.9
Exploitability Score: 8.6
Base Score: 5.5
Impact Score: 3.6
Exploitability Score: 1.8
cpe:2.3:a:openbsd:libressl:*:*:*:*:*:*:*:* versions up to 3.4.0 (inclusive)