OpenSSL

OpenSSL

326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 15.4%
  • Veröffentlicht 04.05.2017 19:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be...

  • EPSS 12.87%
  • Veröffentlicht 04.05.2017 19:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers ...

  • EPSS 30.22%
  • Veröffentlicht 26.09.2016 19:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.

  • EPSS 70.22%
  • Veröffentlicht 26.09.2016 19:59:06
  • Zuletzt bearbeitet 06.05.2026 22:30:45

statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.

  • EPSS 14.07%
  • Veröffentlicht 26.09.2016 19:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted DTLS messages.

  • EPSS 13.84%
  • Veröffentlicht 26.09.2016 19:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem...

  • EPSS 41.68%
  • Veröffentlicht 26.09.2016 19:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.

Exploit
  • EPSS 16%
  • Veröffentlicht 26.09.2016 19:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.

  • EPSS 63.03%
  • Veröffentlicht 26.09.2016 19:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.

  • EPSS 31.99%
  • Veröffentlicht 16.09.2016 05:59:13
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vect...