OpenSSL

OpenSSL

326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Exploit
  • EPSS 100%
  • Veröffentlicht 07.04.2014 22:55:03
  • Zuletzt bearbeitet 21.04.2026 20:07:16

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer ov...

  • EPSS 0.94%
  • Veröffentlicht 25.03.2014 13:25:21
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack.

  • EPSS 11.85%
  • Veröffentlicht 09.01.2014 01:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

  • EPSS 14.54%
  • Veröffentlicht 01.01.2014 16:05:15
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a differe...

  • EPSS 21.17%
  • Veröffentlicht 23.12.2013 22:55:03
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 cl...

  • EPSS 35.58%
  • Veröffentlicht 08.02.2013 19:55:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding,...

  • EPSS 39.59%
  • Veröffentlicht 08.02.2013 19:55:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of service (application crash) via crafted CBC data.

  • EPSS 19.65%
  • Veröffentlicht 08.02.2013 19:55:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) vi...

  • EPSS 2.09%
  • Veröffentlicht 20.06.2012 17:55:01
  • Zuletzt bearbeitet 16.06.2026 23:35:56

The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traf...

  • EPSS 67.19%
  • Veröffentlicht 16.06.2012 21:55:02
  • Zuletzt bearbeitet 16.06.2026 23:29:24

OpenSSL before 0.9.8l, and 0.9.8m through 1.x, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing ma...