Skip to main content

Vendor archive

openssl CVEs

Beta · best-effort

292 CVEs tagged to vendor openssl19 Critical, 91 High, 166 Medium, 16 Low, 0 Unrated.

CVE-2014-0221

Published Jun 5, 2014

The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (…

CVSS 4.3 · Medium
evidence mentions
3
Buzz score
21.9

CVE-2014-0198

Published May 6, 2014

The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive…

CVSS 4.3 · Medium
evidence mentions
4
Buzz score
24.1

CVE-2010-5298

Published Apr 14, 2014

Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessi…

CVSS 4.0 · Medium
evidence mentions
4
Buzz score
24.1

CVE-2014-0076

Published Mar 25, 2014

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to…

CVSS 1.9 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2013-4353

Published Jan 9, 2014

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6450

Published Jan 1, 2014

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6449

Published Dec 23, 2013

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0166

Published Feb 8, 2013

OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2686

Published Feb 8, 2013

crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of ser…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5095

Published Jun 20, 2012

The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-mid…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1473

Published Jun 16, 2012

OpenSSL before 0.9.8l, and 0.9.8m through 1.x, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote at…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2333

Published May 14, 2012

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to ca…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2131

Published Apr 24, 2012

Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory cor…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-2110

Published Apr 19, 2012

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which all…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1165

Published Mar 15, 2012

The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0884

Published Mar 13, 2012

The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict certain oracle behavior, which makes…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7250

Published Feb 29, 2012

The mime_hdr_cmp function in crypto/asn1/asn_mime.c in OpenSSL 0.9.8t and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application cr…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4354

Published Jan 27, 2012

crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an in…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0050

Published Jan 19, 2012

OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an out…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0027

Published Jan 6, 2012

The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4619

Published Jan 6, 2012

The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cau…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4577

Published Jan 6, 2012

OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, allows remote attackers to cause a denial of service (assertion failure) via an X.509 certificate co…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 292 CVEsPage 9 of 12