OpenSSL

OpenSSL

275 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 7.93%
  • Veröffentlicht 19.03.2015 22:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (s2_lib.c assertion failure and daemon exit) via a crafted CLIENT-MASTER-KEY me...

Exploit
  • EPSS 6.63%
  • Veröffentlicht 19.03.2015 22:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding implementation in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (memory corru...

  • EPSS 33.22%
  • Veröffentlicht 19.03.2015 22:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The sigalgs implementation in t1_lib.c in OpenSSL 1.0.2 before 1.0.2a allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) by using an invalid signature_algorithms extension in the ClientHello message durin...

  • EPSS 32.56%
  • Veröffentlicht 19.03.2015 22:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The multi-block feature in the ssl3_write_bytes function in s3_pkt.c in OpenSSL 1.0.2 before 1.0.2a on 64-bit x86 platforms with AES NI support does not properly handle certain non-blocking I/O cases, which allows remote attackers to cause a denial o...

  • EPSS 5.79%
  • Veröffentlicht 19.03.2015 22:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly handle a lack of outer ContentInfo, which allows attackers to cause a denial of service (NULL pointer dereference...

  • EPSS 6.75%
  • Veröffentlicht 19.03.2015 22:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The X509_to_X509_REQ function in crypto/x509/x509_req.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow attackers to cause a denial of service (NULL pointer dereference and application crash) v...

  • EPSS 4.94%
  • Veröffentlicht 19.03.2015 22:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial o...

  • EPSS 23.55%
  • Veröffentlicht 19.03.2015 22:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ASN1_TYPE_cmp function in crypto/asn1/a_type.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly perform boolean-type comparisons, which allows remote attackers to cause a denial of ser...

  • EPSS 8.55%
  • Veröffentlicht 19.03.2015 22:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ssl3_client_hello function in s3_clnt.c in OpenSSL 1.0.2 before 1.0.2a does not ensure that the PRNG is seeded before proceeding with a handshake, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by sniffin...

  • EPSS 2.5%
  • Veröffentlicht 19.03.2015 22:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_asn1.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow remote attackers to cause a denial of service (memory corrup...