Vulnerability index

Browse CVEs

11 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

OpenSSL CRITICAL 9.8
CVE-2022-2274EPSS 45%

The OpenSSL 3.0.4 release introduced a serious bug in the RSA implementation for X86_64 CPUs supporting the AVX512IFMA instructions. This issue makes…

No fix yet
Fix from $2,300 2022-07-01
OpenSSL CRITICAL 9.8
CVE-2016-2182EPSS 44%

The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to …

Mitigation only
Fix from $2,300 2016-09-16
OpenSSL HIGH 7.5
CVE-2016-2181EPSS 23%

The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large seq…

Mitigation only
Fix from $1,950 2016-09-16
OpenSSL HIGH 7.5
CVE-2016-2179EPSS 27%

The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages…

Mitigation only
Fix from $1,950 2016-09-16
OpenSSL CRITICAL 9.8
CVE-2016-0799EPSS 32%

The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows…

Mitigation only
Fix from $2,300 2016-03-03
OpenSSL MEDIUM 5.9
CVE-2016-0800EPSS 82%

The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message bef…

Mitigation only
Fix from $1,600 2016-03-01
OpenSSL MEDIUM 5.0
CVE-2013-0166EPSS 20%

OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows…

Mitigation only
Fix from $1,600 2013-02-08
OpenSSL MEDIUM 5.0
CVE-2003-0147EPSS 6%

OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using…

Mitigation only
Fix from $1,600 2003-03-31
OpenSSL HIGH 7.5
CVE-2002-0655EPSS 8%

OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could …

Mitigation only
Fix from $1,950 2002-08-12
OpenSSL HIGH 7.5
CVE-2002-0656EPSS 90%

Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client …

Mitigation only
Fix from $1,950 2002-08-12
OpenSSL MEDIUM 5.0
CVE-2002-0659EPSS 36%

The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodin…

Mitigation only
Fix from $1,600 2002-08-12