Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

OpenSSL HIGH 7.5
CVE-2016-2179EPSS 27%

The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages…

Mitigation only
Fix from $1,950 2016-09-16
OpenSSL HIGH 7.5
CVE-2016-2180EPSS 29%

The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL throug…

Patch available
Fix from $1,950 2016-08-01
OpenSSL MEDIUM 5.5
CVE-2016-2178

The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which ma…

Fix: 0.10.47 / 0.12.16+
Fix from $1,600 2016-06-20
OpenSSL CRITICAL 9.8
CVE-2016-2177EPSS 45%

OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of s…

Patch available
Fix from $2,300 2016-06-20
OpenSSL HIGH 7.5
CVE-2016-2109EPSS 29%

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remo…

Fix: after 1.0.1s
Fix from $1,950 2016-05-05
OpenSSL HIGH 7.5
CVE-2016-2106EPSS 27%

Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers t…

Fix: after 1.0.1s
Fix from $1,950 2016-05-05
OpenSSL CRITICAL 9.8
CVE-2016-0799EPSS 32%

The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows…

Mitigation only
Fix from $2,300 2016-03-03
OpenSSL MEDIUM 5.9
CVE-2016-0800EPSS 82%

The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message bef…

Mitigation only
Fix from $1,600 2016-03-01
OpenSSL MEDIUM 5.9
CVE-2015-3197EPSS 11%

ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-m…

Patch available
Fix from $1,600 2016-02-15
OpenSSL MEDIUM 6.5
CVE-2015-1793EPSS 62%

The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constrain…

Fix: after 2.0.0.6
Fix from $1,600 2015-07-09
OpenSSL HIGH 7.5
CVE-2015-1789EPSS 74%

The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b all…

Fix: after 1121
Fix from $1,950 2015-06-12
OpenSSL HIGH 7.4
CVE-2014-0224EPSS 95%

OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows…

Fix: 0.9.8za / 1.0.0m+
Fix from $1,950 2014-06-05
OpenSSL MEDIUM 6.8
CVE-2014-0195EPSS 100%

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validat…

Fix: 0.9.8za / 1.0.0m+
Fix from $1,600 2014-06-05
OpenSSL HIGH 7.5
CVE-2014-0160 KEVEPSS 100%

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attac…

Fix: 1.0.1g+
Fix from $1,950 2014-04-07
OpenSSL MEDIUM 5.0
CVE-2013-0166EPSS 20%

OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows…

Mitigation only
Fix from $1,600 2013-02-08
OpenSSL MEDIUM 6.8
CVE-2012-2333EPSS 28%

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption,…

Fix: after 0.9.8w
Fix from $1,600 2012-05-14
OpenSSL HIGH 7.5
CVE-2012-2110EPSS 48%

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly int…

Fix: after 0.9.8u
Fix from $1,950 2012-04-19
OpenSSL MEDIUM 5.0
CVE-2009-4355EPSS 9%

Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote at…

Fix: after 0.9.8l
Fix from $1,600 2010-01-14
OpenSSL MEDIUM 5.1
CVE-2009-2409

The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other…

Fix: 2.6.4 / 2.7.4+
Fix from $1,600 2009-07-30
OpenSSL MEDIUM 5.0
CVE-2009-1386EPSS 80%

ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS Cha…

Fix: 0.9.8i+
Fix from $1,600 2009-06-04
OpenSSL MEDIUM 5.0
CVE-2009-1387EPSS 10%

The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (N…

Fix: 0.9.8m+
Fix from $1,600 2009-06-04
Fips Object Module MEDIUM 6.4
CVE-2007-5502

The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data…

Patch available
Fix from $1,600 2007-12-01
OpenSSL MEDIUM 5.0
CVE-2003-0147EPSS 6%

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using…

Mitigation only
Fix from $1,600 2003-03-31
OpenSSL MEDIUM 5.0
CVE-2003-0078EPSS 14%

ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding…

Fix: 0.9.6i+
Fix from $1,600 2003-03-03
OpenSSL HIGH 7.5
CVE-2002-0655EPSS 8%

OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could …

Mitigation only
Fix from $1,950 2002-08-12
OpenSSL HIGH 7.5
CVE-2002-0656EPSS 90%

Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client …

Mitigation only
Fix from $1,950 2002-08-12
OpenSSL MEDIUM 5.0
CVE-2002-0659EPSS 36%

The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodin…

Mitigation only
Fix from $1,600 2002-08-12
OpenSSL MEDIUM 5.0
CVE-2001-1141

The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine …

Patch available
Fix from $1,600 2001-07-10
OpenSSL MEDIUM 5.0
CVE-2000-0535

OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD…

Patch available
Fix from $1,600 2000-06-12