CVE-2014-3566
- EPSS 94.02%
- Veröffentlicht 15.10.2014 00:55:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
- EPSS 46.88%
- Veröffentlicht 13.08.2014 23:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Double free vulnerability in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (application crash) via crafted DTLS packets that tri...
- EPSS 51.73%
- Veröffentlicht 13.08.2014 23:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (memory consumption) via crafted DTLS handshake messages that trigger memory alloc...
- EPSS 66.03%
- Veröffentlicht 13.08.2014 23:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Memory leak in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (memory consumption) via zero-length DTLS fragments that trigger im...
CVE-2014-3508
- EPSS 3.12%
- Veröffentlicht 13.08.2014 23:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i, when pretty printing is used, does not ensure the presence of '\0' characters, which allows context-dependent attacker...
CVE-2014-3509
- EPSS 12.97%
- Veröffentlicht 13.08.2014 23:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the ssl_parse_serverhello_tlsext function in t1_lib.c in OpenSSL 1.0.0 before 1.0.0n and 1.0.1 before 1.0.1i, when multithreading and session resumption are used, allows remote SSL servers to cause a denial of service (memory overwr...
CVE-2014-3510
- EPSS 14.8%
- Veröffentlicht 13.08.2014 23:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote DTLS servers to cause a denial of service (NULL pointer dereference and client application crash) via ...
CVE-2014-3511
- EPSS 5.42%
- Veröffentlicht 13.08.2014 23:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both sup...
CVE-2014-3512
- EPSS 40.21%
- Veröffentlicht 13.08.2014 23:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid SRP (1) g, (2)...
CVE-2014-5139
- EPSS 34.03%
- Veröffentlicht 13.08.2014 23:55:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite ...