OpenSSL

OpenSSL

262 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.44%
  • Published 19.05.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, ak...

Exploit
  • EPSS 15.69%
  • Published 19.05.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Multiple memory leaks in the dtls1_process_out_of_seq_message function in ssl/d1_both.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allow remote attackers to cause a denial of service (memory consumption) via DTLS records that (1) are duplicates or ...

Exploit
  • EPSS 8.31%
  • Published 19.05.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

Use-after-free vulnerability in the dtls1_retrieve_buffered_fragment function in ssl/d1_both.c in OpenSSL 1.0.0 Beta 2 allows remote attackers to cause a denial of service (openssl s_client crash) and possibly have unspecified other impact via a DTLS...

  • EPSS 2.73%
  • Published 27.03.2009 16:30:02
  • Last modified 09.04.2025 00:30:58

OpenSSL before 0.9.8k on WIN64 and certain other platforms does not properly handle a malformed ASN.1 structure, which allows remote attackers to cause a denial of service (invalid memory access and application crash) by placing this structure in the...

  • EPSS 1.8%
  • Published 27.03.2009 16:30:01
  • Last modified 09.04.2025 00:30:58

The CMS_verify function in OpenSSL 0.9.8h through 0.9.8j, when CMS is enabled, does not properly handle errors associated with malformed signed attributes, which allows remote attackers to repudiate a signature that originally appeared to be valid bu...

  • EPSS 10.02%
  • Published 27.03.2009 16:30:00
  • Last modified 09.04.2025 00:30:58

The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid ...

Exploit
  • EPSS 0.26%
  • Published 20.02.2009 19:30:00
  • Last modified 09.04.2025 00:30:58

OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack, a related issue to CVE-2002-0970.

  • EPSS 1.04%
  • Published 07.01.2009 17:30:00
  • Last modified 09.04.2025 00:30:58

OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.

Exploit
  • EPSS 8.14%
  • Published 10.07.2008 17:41:00
  • Last modified 09.04.2025 00:30:58

Memory leak in the zlib_stateful_init function in crypto/comp/c_zlib.c in libssl in OpenSSL 0.9.8f through 0.9.8h allows remote attackers to cause a denial of service (memory consumption) via multiple calls, as demonstrated by initial SSL client hand...

  • EPSS 12.83%
  • Published 29.05.2008 16:32:00
  • Last modified 09.04.2025 00:30:58

Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from ...