CVE-2017-3732
- EPSS 15.4%
- Veröffentlicht 04.05.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be...
CVE-2017-3733
- EPSS 12.87%
- Veröffentlicht 04.05.2017 19:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa) then this can cause OpenSSL 1.1.0 before 1.1.0e to crash (dependent on ciphersuite). Both clients and servers ...
CVE-2016-7052
- EPSS 30.22%
- Veröffentlicht 26.09.2016 19:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.
- EPSS 70.22%
- Veröffentlicht 26.09.2016 19:59:06
- Zuletzt bearbeitet 06.05.2026 22:30:45
statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.
CVE-2016-6308
- EPSS 14.07%
- Veröffentlicht 26.09.2016 19:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted DTLS messages.
CVE-2016-6307
- EPSS 13.84%
- Veröffentlicht 26.09.2016 19:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem...
CVE-2016-6306
- EPSS 41.68%
- Veröffentlicht 26.09.2016 19:59:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
CVE-2016-6305
- EPSS 16%
- Veröffentlicht 26.09.2016 19:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ssl3_read_bytes function in record/rec_layer_s3.c in OpenSSL 1.1.0 before 1.1.0a allows remote attackers to cause a denial of service (infinite loop) by triggering a zero-length record in an SSL_peek call.
CVE-2016-6304
- EPSS 63.03%
- Veröffentlicht 26.09.2016 19:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
CVE-2016-6303
- EPSS 31.99%
- Veröffentlicht 16.09.2016 05:59:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vect...