OpenSSL

OpenSSL

326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.98%
  • Veröffentlicht 06.12.2015 20:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segmentation fault) via a zero p value in an anonymous Diffie-Hellman (DH) ServerKeyExchange message.

  • EPSS 61.8%
  • Veröffentlicht 09.07.2015 19:17:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers t...

  • EPSS 4.3%
  • Veröffentlicht 07.07.2015 10:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Race condition in a certain Red Hat patch to the PRNG lock implementation in the ssleay_rand_bytes function in OpenSSL, as distributed in openssl-1.0.1e-25.el7 in Red Hat Enterprise Linux (RHEL) 7 and other products, allows remote attackers to cause ...

  • EPSS 22.48%
  • Veröffentlicht 12.06.2015 19:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (infinite loop) via vectors that trigger a NULL valu...

  • EPSS 15.97%
  • Veröffentlicht 12.06.2015 19:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b, when used for a multi-threaded client, allows remote attackers to cause a denial...

  • EPSS 22.9%
  • Veröffentlicht 12.06.2015 19:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash)...

  • EPSS 74.48%
  • Veröffentlicht 12.06.2015 19:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a cr...

  • EPSS 23.22%
  • Veröffentlicht 12.06.2015 19:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenSSL before 0.9.8s, 1.0.0 before 1.0.0e, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b does not properly handle ECParameters structures in which the curve is over a malformed binary polynomial ...

Exploit
  • EPSS 16.59%
  • Veröffentlicht 12.06.2015 19:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The dtls1_clear_queues function in ssl/d1_lib.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h frees data structures without considering that application data can arrive between a ChangeCipherSpec message and a Finished messa...

  • EPSS 99.86%
  • Veröffentlicht 21.05.2015 00:59:00
  • Zuletzt bearbeitet 27.05.2026 17:16:21

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a Clie...