- EPSS 3.44%
- Published 19.05.2009 19:30:00
- Last modified 09.04.2025 00:30:58
The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, ak...
- EPSS 15.69%
- Published 19.05.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or ...
- EPSS 8.31%
- Published 19.05.2009 19:30:00
- Last modified 09.04.2025 00:30:58
Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS...
- EPSS 2.73%
- Published 27.03.2009 16:30:02
- Last modified 09.04.2025 00:30:58
OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invalid memory access and application crash) by placing this structure in the...
CVE-2009-0591
- EPSS 1.8%
- Published 27.03.2009 16:30:01
- Last modified 09.04.2025 00:30:58
The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid bu...
- EPSS 10.02%
- Published 27.03.2009 16:30:00
- Last modified 09.04.2025 00:30:58
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid ...
CVE-2009-0653
- EPSS 0.26%
- Published 20.02.2009 19:30:00
- Last modified 09.04.2025 00:30:58
OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack, a related issue to CVE-2002-0970.
CVE-2008-5077
- EPSS 1.04%
- Published 07.01.2009 17:30:00
- Last modified 09.04.2025 00:30:58
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
- EPSS 8.14%
- Published 10.07.2008 17:41:00
- Last modified 09.04.2025 00:30:58
Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client hand...
CVE-2008-0891
- EPSS 12.83%
- Published 29.05.2008 16:32:00
- Last modified 09.04.2025 00:30:58
Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from ...