Search

Found 160 results in 104ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-31790 high 7.5 7.5 FIX rhel slesdebian debian opensslgoogle 16d ago Moderate: openssl security update
CVE-2026-31789 critical 9.8 9.8 FIX slesdebian debian opensslgoogle 2mo ago Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a cr…
CVE-2026-28390 high 7.5 7.5 FIX slesdebian debian rhel opensslgoogle 2mo ago Moderate: compat-openssl11 security update
CVE-2026-28389 high 7.5 7.5 FIX slesdebian debian opensslgoogle 2mo ago Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlle…
CVE-2026-28388 high 7.5 7.5 FIX debian debian opensslgoogle 2mo ago Issue summary: When a delta CRL that contains a Delta CRL Indicator extension is processed a NULL pointer dereference might happen if the required CRL Number extension is missing. Impact summary: A …
CVE-2026-28387 high 8.1 8.1 FIX slesdebian debian opensslgoogle 2mo ago Issue summary: An uncommon configuration of clients performing DANE TLSA-based server authentication, when paired with uncommon server DANE TLSA records, may result in a use-after-free and/or double-…
CVE-2026-22796 medium 5.3 5.3 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2026-22795 medium 5.5 5.5 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-69421 high 7.5 7.5 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-69420 high 7.5 7.5 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-69419 high 7.4 7.4 FIX rhel sles rocky openssl 4mo ago RHSA-2026:3042: openssl security update (Moderate)
CVE-2025-69418 medium 4.0 4.0 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-68160 medium 4.7 4.7 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2025-15467 high 8.8 8.8 FIX rhel sles rocky openssl 4mo ago Important: openssl security update
CVE-2024-6119 high 7.5 7.5 FIX rhel sles rocky opensslnetapp 2y ago Moderate: openssl security update
CVE-2024-0727 medium 5.5 5.5 FIX rhelalmalinux almalinux sles openssl 2y ago Low: openssl and openssl-fips-provider security update
CVE-2023-6129 medium 6.5 6.5 FIX rhel sles rocky openssl 2y ago Low: openssl and openssl-fips-provider security update
CVE-2023-5678 medium 5.3 5.3 FIX rocky rhel sles openssl 2y ago RHSA-2023:7877: openssl security update (Low)
CVE-2023-5363 high 7.5 7.5 FIX rhelarch arch sles openssl 2y ago Moderate: openssl security update
CVE-2022-0778 high 7.5 7.5 FIX rhel sles rocky opensslnetapptenable 4y ago RHSA-2022:5326: compat-openssl10 security update (Low)
CVE-2020-1971 medium 5.9 5.9 FIX arch arch slesdebian debian openssloraclenetapp 6y ago RHSA-2020:5476: openssl security and bug fix update (Important)
CVE-2017-3738 medium 5.9 5.9 FIX arch arch slesdebian debian opensslnodejs 9y ago There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA…
CVE-2017-3737 medium 5.9 5.9 FIX arch arch slesdebian debian openssl 9y ago OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into the error state and w…
CVE-2016-8610 high 7.5 7.5 FIX sles rheldebian debian opensslredhatnetapp 9y ago A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote…
CVE-2017-3736 medium 6.5 6.5 FIX arch arch slesdebian debian openssl 9y ago There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RS…
CVE-2017-3735 medium 5.3 5.3 FIX arch arch slesdebian debian openssl 9y ago While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been pres…
CVE-2016-7055 medium 5.9 5.9 FIX slesarch archdebian debian opensslnodejs 9y ago There is a carry propagating bug in the Broadwell-specific Montgomery multiplication procedure in OpenSSL 1.0.2 and 1.1.0 before 1.1.0c that handles input lengths divisible by, but longer than 256 bi…
CVE-2017-3733 high 7.5 7.5 FIX debian debian opensslhp 9y ago During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (d…
CVE-2017-3732 medium 5.9 5.9 FIX arch arch slesdebian debian opensslnodejs 9y ago There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks agai…
CVE-2017-3731 high 7.5 7.5 FIX arch arch slesdebian debian opensslnodejs 9y ago If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resu…
CVE-2017-3730 high 7.5 8.5 EXPFIX slesdebian debian openssloracle 9y ago In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a …
CVE-2016-7054 high 7.5 8.5 EXPFIX arch archdebian debian openssl 9y ago In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue i…
CVE-2016-7053 high 7.5 7.5 FIX arch archdebian debian openssl 9y ago In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference. This is caused by a bug in the handling of the ASN.1 CHOICE type in OpenSSL 1.1.…
CVE-2016-7052 high 7.5 7.5 FIX arch archdebian debian opensslnodejs 10y ago crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.
CVE-2016-6309 critical 9.8 9.8 FIX arch archdebian debian openssl 10y ago statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitra…
CVE-2016-6308 medium 5.9 5.9 FIX slesdebian debian openssl 10y ago statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of servic…
CVE-2016-6307 medium 5.9 5.9 FIX debian debian openssl 10y ago The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consu…
CVE-2016-6306 medium 5.9 5.9 FIX slesarch archdebian debian opensslhpnodejs 10y ago The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s…
CVE-2016-6305 high 7.5 7.5 FIX debian debian openssl 10y ago The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_…
CVE-2016-6304 high 7.5 7.5 FIX slesarch archdebian debian opensslnodejs 10y ago Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status…
CVE-2016-6303 critical 9.8 9.8 FIX slesarch archdebian debian nodejsopenssl 10y ago Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or poss…
CVE-2016-6302 high 7.5 7.5 FIX slesarch archdebian debian openssl 10y ago The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of serv…
CVE-2016-2182 critical 9.8 9.8 FIX slesarch archdebian debian hpopenssl 10y ago The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and…
CVE-2016-2181 high 7.5 7.5 FIX slesarch archdebian debian openssl 10y ago The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cau…
CVE-2016-2179 high 7.5 7.5 FIX slesarch archdebian debian openssl 10y ago The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial …
CVE-2016-2183 high 7.5 7.5 FIX slesarch arch rhel redhatpythoncisco 10y ago The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for re…
CVE-2016-2180 high 7.5 7.5 FIX slesarch archdebian debian openssl 10y ago The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial…
CVE-2016-2178 medium 5.5 5.5 FIX slesarch archubuntu ubuntu opensslnodejs 10y ago The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA pr…
CVE-2016-2177 critical 9.8 9.8 FIX slesarch archdebian debian hpopenssl 10y ago OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or…
CVE-2016-2176 high 8.2 8.2 FIX debian debian openssl 10y ago The X509_NAME_oneline function in crypto/x509/x509_obj.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to obtain sensitive information from process stack memory or cause a …
CVE-2016-2109 high 7.5 7.5 FIX slesdebian debian rhel openssl 10y ago The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory …
CVE-2016-2108 critical 9.8 9.8 FIX slesdebian debian rhel openssl 10y ago The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via a…
CVE-2016-2107 medium 5.9 6.9 EXPFIX sles rhelsuse suse opensslhpnodejs 10y ago The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleart…
CVE-2016-2106 high 7.5 7.5 FIX slesdebian debian rhel openssl 10y ago Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruptio…
CVE-2016-2105 high 7.5 7.5 FIX sles rhelsuse suse oracleopensslnodejs 10y ago Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption)…
CVE-2000-1254 high 7.5 7.5 FIX debian debian openssl 10y ago crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryptographic protection…
CVE-2016-2842 critical 9.8 9.8 FIX debian debian openssl 10y ago The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows remote attackers to cau…
CVE-2016-0799 critical 9.8 9.8 FIX slesdebian debian opensslpulsesecure 10y ago The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a denial of service (ov…
CVE-2016-0798 high 7.5 7.5 FIX slesdebian debian openssl 10y ago Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory consumption) by providing a…
CVE-2016-0797 high 7.5 7.5 FIX debian debianubuntu ubuntu opensslnodejs 10y ago Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly …
CVE-2016-0705 critical 9.8 9.8 FIX debian debianubuntu ubuntu oracleopenssl 10y ago Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory…
CVE-2016-0702 medium 5.1 5.1 FIX debian debianubuntu ubuntu opensslnodejs 10y ago The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiati…
CVE-2016-0704 medium 5.9 5.9 FIX debian debian openssl 10y ago An oracle protection mechanism in the get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0…
CVE-2016-0703 medium 5.9 5.9 FIX debian debian openssl 10y ago The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a accepts a nonzero CLIENT-MASTE…
CVE-2016-0800 medium 5.9 6.9 EXPFIX debian debian opensslpulsesecure 10y ago The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain p…
CVE-2016-0701 low 3.7 3.7 FIX slesdebian debian openssl 10y ago The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for…
CVE-2015-3197 medium 5.9 5.9 FIX slesdebian debian oracleopenssl 10y ago ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-middle attackers to defeat cryptographic protection…
CVE-2015-3196 medium 4.3 FIX slesdebian debianfedora fedora hpopenssloracle 11y ago ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which a…
CVE-2015-3195 medium 5.3 5.3 FIX macos macossuse susedebian debian oracleopenssl 11y ago The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_…
CVE-2015-3194 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu opensslnodejs 11y ago crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.…
CVE-2015-3193 high 7.5 7.5 FIX slesubuntu ubuntudebian debian opensslnodejs 11y ago The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and pro…
CVE-2015-1794 medium 5.0 FIX slesdebian debian openssl 11y ago The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-He…
CVE-2015-1793 medium 6.5 7.5 EXPFIX debian debian oracleopenssl 11y ago The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative …
CVE-2015-3216 medium 4.3 FIX rheldebian debian openssl 11y ago Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 an…
CVE-2015-1792 medium 5.0 FIX debian debian openssl 11y ago The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (…
CVE-2015-1791 medium 6.8 FIX debian debian openssl 11y ago Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b, when used for a multi-threade…
CVE-2015-1790 medium 5.0 FIX debian debian openssl 11y ago The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of servi…
CVE-2015-1789 high 7.5 7.5 FIX debian debian openssloracle 11y ago The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service …
CVE-2015-1788 medium 4.3 FIX debian debian openssl 11y ago The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenSSL before 0.9.8s, 1.0.0 before 1.0.0e, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b does not properly handle ECParameters structures in whi…
CVE-2014-8176 high 7.5 FIX debian debian openssl 11y ago The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive betw…
CVE-2015-4000 low 3.7 4.7 EXPFIX slesdebian debianmacos macos opensslibmoracle 11y ago The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to c…
CVE-2015-1787 low 2.6 FIX debian debian openssl 11y ago The ssl3_get_client_key_exchange function in s3_srvr.c in OpenSSL 1.0.2 before 1.0.2a, when client authentication and an ephemeral Diffie-Hellman ciphersuite are enabled, allows remote attackers to c…
CVE-2015-0293 medium 5.0 FIX debian debian openssl 11y ago The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (s2_lib.c assertion failure …
CVE-2015-0292 high 7.5 FIX debian debian openssl 11y ago Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding implementation in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote a…
CVE-2015-0291 medium 5.0 FIX debian debian openssl 11y ago The sigalgs implementation in t1_lib.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by using an invalid signature_al…
CVE-2015-0290 medium 5.0 FIX debian debian openssl 11y ago The multi-block feature in the ssl3_write_bytes function in s3_pkt.c in OpenSSL 1.0.2 before 1.0.2a on 64-bit x86 platforms with AES NI support does not properly handle certain non-blocking I/O cases…
CVE-2015-0289 medium 5.0 FIX debian debian openssl 11y ago The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly handle a lack of outer ContentInfo, which allows attackers to …
CVE-2015-0288 medium 5.0 FIX debian debian openssl 11y ago The X509_to_X509_REQ function in crypto/x509/x509_req.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow attackers to cause a denial of service…
CVE-2015-0287 medium 5.0 FIX debian debian openssl 11y ago The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structur…
CVE-2015-0286 medium 5.0 FIX debian debian openssl 11y ago The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly perform boolean-type comparisons, whi…
CVE-2015-0285 medium 4.3 FIX debian debian openssl 11y ago The ssl3_client_hello function in s3_clnt.c in OpenSSL 1.0.2 before 1.0.2a does not ensure that the PRNG is seeded before proceeding with a handshake, which makes it easier for remote attackers to de…
CVE-2015-0209 medium 6.8 FIX debian debian openssl 11y ago Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_asn1.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow remote at…
CVE-2015-0208 medium 4.3 FIX debian debian openssl 11y ago The ASN.1 signature-verification implementation in the rsa_item_verify function in crypto/rsa/rsa_ameth.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL poi…
CVE-2015-0207 medium 5.0 FIX debian debian openssl 11y ago The dtls1_listen function in d1_lib.c in OpenSSL 1.0.2 before 1.0.2a does not properly isolate the state information of independent data streams, which allows remote attackers to cause a denial of se…
CVE-2015-0206 medium 5.0 FIX debian debian openssl 12y ago Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (memory consumption) by sending…
CVE-2015-0205 medium 5.0 FIX debian debian openssl 12y ago The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a Certific…
CVE-2015-0204 medium 4.3 FIX slesdebian debian openssl 12y ago The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct RSA-to-EXPORT_RSA downgrade attacks and fa…
CVE-2014-8275 medium 5.0 FIX debian debian openssl 12y ago OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k does not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-…
CVE-2014-3572 medium 5.0 FIX debian debian openssl 12y ago The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigge…
CVE-2014-3571 medium 5.0 FIX debian debian openssl 12y ago OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DTLS message t…