Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2016-2179EPSS 27%
The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages…
OpenSSL
Mitigation only
HIGH 7.5
CVE-2016-2180EPSS 29%
The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL throug…
OpenSSL
Patch available
MEDIUM 5.5
CVE-2016-2178
The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which ma…
OpenSSL
0.10.47 / 0.12.16+
CRITICAL 9.8
CVE-2016-2177EPSS 45%
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of s…
OpenSSL
Patch available
HIGH 7.5
CVE-2016-2109EPSS 29%
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remo…
OpenSSL
after 1.0.1s
HIGH 7.5
CVE-2016-2106EPSS 27%
Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers t…
OpenSSL
after 1.0.1s
CRITICAL 9.8
CVE-2016-0799EPSS 32%
The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows…
OpenSSL
Mitigation only
MEDIUM 5.9
CVE-2016-0800EPSS 82%
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message bef…
OpenSSL
Mitigation only
MEDIUM 5.9
CVE-2015-3197EPSS 11%
ssl/s2_srvr.c in OpenSSL 1.0.1 before 1.0.1r and 1.0.2 before 1.0.2f does not prevent use of disabled ciphers, which makes it easier for man-in-the-m…
OpenSSL
Patch available
MEDIUM 6.5
CVE-2015-1793EPSS 62%
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constrain…
OpenSSL
after 2.0.0.6
HIGH 7.5
CVE-2015-1789EPSS 74%
The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b all…
OpenSSL
after 1121
HIGH 7.4
CVE-2014-0224EPSS 95%
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows…
OpenSSL
0.9.8za / 1.0.0m+
MEDIUM 6.8
CVE-2014-0195EPSS 100%
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validat…
OpenSSL
0.9.8za / 1.0.0m+
HIGH 7.5
CVE-2014-0160 KEVEPSS 100%
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attac…
OpenSSL
1.0.1g+
MEDIUM 5.0
CVE-2013-0166EPSS 20%
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows…
OpenSSL
Mitigation only
MEDIUM 6.8
CVE-2012-2333EPSS 28%
Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption,…
OpenSSL
after 0.9.8w
HIGH 7.5
CVE-2012-2110EPSS 48%
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly int…
OpenSSL
after 0.9.8u
MEDIUM 5.0
CVE-2009-4355EPSS 9%
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote at…
OpenSSL
after 0.9.8l
MEDIUM 5.1
CVE-2009-2409
The Network Security Services (NSS) library before 3.12.3, as used in Firefox; GnuTLS before 2.6.4 and 2.7.4; OpenSSL 0.9.8 through 0.9.8k; and other…
OpenSSL
2.6.4 / 2.7.4+
MEDIUM 5.0
CVE-2009-1386EPSS 80%
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS Cha…
OpenSSL
0.9.8i+
MEDIUM 5.0
CVE-2009-1387EPSS 10%
The dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL before 1.0.0 Beta 2 allows remote attackers to cause a denial of service (N…
OpenSSL
0.9.8m+
MEDIUM 6.4
CVE-2007-5502
The PRNG implementation for the OpenSSL FIPS Object Module 1.1.1 does not perform auto-seeding during the FIPS self-test, which generates random data…
Fips Object Module
Patch available
MEDIUM 5.0
CVE-2003-0147EPSS 6%
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using…
OpenSSL
Mitigation only
MEDIUM 5.0
CVE-2003-0078EPSS 14%
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding…
OpenSSL
0.9.6i+
HIGH 7.5
CVE-2002-0655EPSS 8%
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could …
OpenSSL
Mitigation only
HIGH 7.5
CVE-2002-0656EPSS 90%
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client …
OpenSSL
Mitigation only
MEDIUM 5.0
CVE-2002-0659EPSS 36%
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodin…
OpenSSL
Mitigation only
MEDIUM 5.0
CVE-2001-1141
The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine …
OpenSSL
Patch available
MEDIUM 5.0
CVE-2000-0535
OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD…
OpenSSL
Patch available