Skip to main content

Vendor archive

openssl CVEs

Beta · best-effort

292 CVEs tagged to vendor openssl19 Critical, 91 High, 166 Medium, 16 Low, 0 Unrated.

CVE-2016-2181

Published Sep 16, 2016

The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows rem…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2179

Published Sep 16, 2016

The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attacker…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2183

Published Sep 1, 2016

The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which ma…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2016-2180

Published Aug 1, 2016

The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attacke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2176

Published May 5, 2016

The X509_NAME_oneline function in crypto/x509/x509_obj.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to obtain sensitive information from process stac…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2016-2109

Published May 5, 2016

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-2108

Published May 5, 2016

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memo…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1

CVE-2016-2107

Published May 5, 2016

The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obt…

CVSS 5.9 · Medium
evidence mentions
10
Buzz score
32.0

CVE-2016-2106

Published May 5, 2016

Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (h…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2016-2105

Published May 5, 2016

Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (hea…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2000-1254

Published May 5, 2016

crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryp…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2842

Published Mar 3, 2016

The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memory allocation succeeds, which allows rem…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-0798

Published Mar 3, 2016

Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to cause a denial of service (memory consump…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2016-0704

Published Mar 2, 2016

An oracle protection mechanism in the get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m,…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-0703

Published Mar 2, 2016

The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a accepts a…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
21.9
Vendor/product tagsBeta · best-effort

CVE-2016-0701

Published Feb 15, 2016

The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which…

CVSS 3.7 · Low
evidence mentions
6
Buzz score
27.5
Vendor/product tagsBeta · best-effort
Showing 126-150 of 292 CVEsPage 6 of 12