CVE-2021-23840
- EPSS 50.73%
- Veröffentlicht 16.02.2021 17:15:13
- Zuletzt bearbeitet 16.04.2026 15:16:45
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value ...
CVE-2021-23841
- EPSS 7.47%
- Veröffentlicht 16.02.2021 17:15:13
- Zuletzt bearbeitet 21.11.2024 05:51:55
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while...
CVE-2020-1971
- EPSS 6.97%
- Veröffentlicht 08.12.2020 16:15:11
- Zuletzt bearbeitet 29.05.2026 16:16:20
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they...
CVE-2020-1968
- EPSS 4.76%
- Veröffentlicht 09.09.2020 14:15:12
- Zuletzt bearbeitet 16.04.2026 15:16:41
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the atta...
CVE-2020-1967
- EPSS 53.34%
- Veröffentlicht 21.04.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:11:45
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occur...
CVE-2019-1551
- EPSS 14.3%
- Veröffentlicht 06.12.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:36:48
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this d...
CVE-2019-1547
- EPSS 1.2%
- Veröffentlicht 10.09.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:36:48
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those case...
CVE-2019-1549
- EPSS 6.23%
- Veröffentlicht 10.09.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:36:48
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this pro...
CVE-2019-1563
- EPSS 3.84%
- Veröffentlicht 10.09.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:36:49
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decryp...
CVE-2019-1552
- EPSS 0.7%
- Veröffentlicht 30.07.2019 17:15:12
- Zuletzt bearbeitet 21.11.2024 04:36:48
OpenSSL has internal defaults for a directory tree where it can find a configuration file as well as certificates used for verification in TLS. This directory is most commonly referred to as OPENSSLDIR, and is configurable with the --prefix / --opens...