OpenSSL

OpenSSL

262 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 28.58%
  • Veröffentlicht 26.09.2016 19:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted DTLS messages.

  • EPSS 15.71%
  • Veröffentlicht 26.09.2016 19:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem...

  • EPSS 9%
  • Veröffentlicht 26.09.2016 19:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.

Exploit
  • EPSS 31.2%
  • Veröffentlicht 26.09.2016 19:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.

  • EPSS 20.28%
  • Veröffentlicht 26.09.2016 19:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.

  • EPSS 32.88%
  • Veröffentlicht 16.09.2016 05:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vect...

  • EPSS 19.8%
  • Veröffentlicht 16.09.2016 05:59:12
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket length, which allows remote attackers to cause a denial of service via a ticket that is too short.

  • EPSS 36.38%
  • Veröffentlicht 16.09.2016 05:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified ot...

  • EPSS 23.03%
  • Veröffentlicht 16.09.2016 05:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a large sequence number, which allows remote attackers to cause a denial of service (false-positive packet drops...

  • EPSS 16.96%
  • Veröffentlicht 16.09.2016 05:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-order messages, which allows remote attackers to cause a denial of service (memory consumption) by maintaining many...