Vulnerability index

Browse CVEs

119 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2016-2179EPSS 27% The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages… OpenSSL Mitigation only Fix from $1,9502016-09-16 HIGH 7.5 CVE-2016-2180EPSS 29% The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL throug… OpenSSL Patch available Fix from $1,9502016-08-01 MEDIUM 5.5 CVE-2016-2178 The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which ma… OpenSSL 0.10.47 / 0.12.16+ Fix from $1,6002016-06-20 CRITICAL 9.8 CVE-2016-2177EPSS 45% OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of s… OpenSSL Patch available Fix from $2,3002016-06-20 HIGH 7.5 CVE-2016-2109EPSS 29% The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remo… OpenSSL after 1.0.1s Fix from $1,9502016-05-05 HIGH 7.5 CVE-2016-2106EPSS 27% Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers t… OpenSSL after 1.0.1s Fix from $1,9502016-05-05 CRITICAL 9.8 CVE-2016-0799EPSS 32% The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows… OpenSSL Mitigation only Fix from $2,3002016-03-03 MEDIUM 5.9 CVE-2016-0800EPSS 82% The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message bef… OpenSSL Mitigation only Fix from $1,6002016-03-01 MEDIUM 5.9 CVE-2015-3197EPSS 11% ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-m… OpenSSL Patch available Fix from $1,6002016-02-15 MEDIUM 6.5 CVE-2015-1793EPSS 62% The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constrain… OpenSSL after 2.0.0.6 Fix from $1,6002015-07-09 HIGH 7.5 CVE-2015-1789EPSS 74% The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b all… OpenSSL after 1121 Fix from $1,9502015-06-12 HIGH 7.4 CVE-2014-0224EPSS 95% OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows… OpenSSL 0.9.8za / 1.0.0m+ Fix from $1,9502014-06-05 MEDIUM 6.8 CVE-2014-0195EPSS 100% The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validat… OpenSSL 0.9.8za / 1.0.0m+ Fix from $1,6002014-06-05 HIGH 7.5 CVE-2014-0160 KEVEPSS 100% The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attac… OpenSSL 1.0.1g+ Fix from $1,9502014-04-07 MEDIUM 5.0 CVE-2013-0166EPSS 20% OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows… OpenSSL Mitigation only Fix from $1,6002013-02-08 MEDIUM 6.8 CVE-2012-2333EPSS 28% Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption,… OpenSSL after 0.9.8w Fix from $1,6002012-05-14 HIGH 7.5 CVE-2012-2110EPSS 48% The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly int… OpenSSL after 0.9.8u Fix from $1,9502012-04-19 MEDIUM 5.0 CVE-2009-4355EPSS 9% Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote at… OpenSSL after 0.9.8l Fix from $1,6002010-01-14 MEDIUM 5.1 CVE-2009-2409 The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other… OpenSSL 2.6.4 / 2.7.4+ Fix from $1,6002009-07-30 MEDIUM 5.0 CVE-2009-1386EPSS 80% ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS Cha… OpenSSL 0.9.8i+ Fix from $1,6002009-06-04 MEDIUM 5.0 CVE-2009-1387EPSS 10% The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (N… OpenSSL 0.9.8m+ Fix from $1,6002009-06-04 MEDIUM 6.4 CVE-2007-5502 The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data… Fips Object Module Patch available Fix from $1,6002007-12-01 MEDIUM 5.0 CVE-2003-0147EPSS 6% OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using… OpenSSL Mitigation only Fix from $1,6002003-03-31 MEDIUM 5.0 CVE-2003-0078EPSS 14% ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding… OpenSSL 0.9.6i+ Fix from $1,6002003-03-03 HIGH 7.5 CVE-2002-0655EPSS 8% OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could … OpenSSL Mitigation only Fix from $1,9502002-08-12 HIGH 7.5 CVE-2002-0656EPSS 90% Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client … OpenSSL Mitigation only Fix from $1,9502002-08-12 MEDIUM 5.0 CVE-2002-0659EPSS 36% The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodin… OpenSSL Mitigation only Fix from $1,6002002-08-12 MEDIUM 5.0 CVE-2001-1141 The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine … OpenSSL Patch available Fix from $1,6002001-07-10 MEDIUM 5.0 CVE-2000-0535 OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD… OpenSSL Patch available Fix from $1,6002000-06-12