OpenSSL

OpenSSL

326 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 28.15%
  • Veröffentlicht 14.05.2012 22:55:03
  • Zuletzt bearbeitet 16.06.2026 23:41:22

Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified...

  • EPSS 17%
  • Veröffentlicht 24.04.2012 20:55:02
  • Zuletzt bearbeitet 16.06.2026 23:41:03

Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER dat...

Exploit
  • EPSS 48.3%
  • Veröffentlicht 19.04.2012 17:55:01
  • Zuletzt bearbeitet 16.06.2026 23:41:00

The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a de...

  • EPSS 6.77%
  • Veröffentlicht 15.03.2012 17:55:00
  • Zuletzt bearbeitet 16.06.2026 23:39:10

The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulne...

  • EPSS 12.93%
  • Veröffentlicht 13.03.2012 03:12:26
  • Zuletzt bearbeitet 16.06.2026 23:38:27

The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict certain oracle behavior, which makes it easier for context-dependent attackers to decrypt data via a Millio...

  • EPSS 6.99%
  • Veröffentlicht 29.02.2012 11:55:04
  • Zuletzt bearbeitet 16.06.2026 22:34:39

The mime_hdr_cmp function in crypto/asn1/asn_mime.c in OpenSSL 0.9.8t and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message.

  • EPSS 4.04%
  • Veröffentlicht 27.01.2012 00:55:01
  • Zuletzt bearbeitet 16.06.2026 23:34:49

crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 ...

  • EPSS 13.86%
  • Veröffentlicht 19.01.2012 19:55:01
  • Zuletzt bearbeitet 16.06.2026 23:36:34

OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an out-of-bounds read. NOTE: this vulnerability exists because of an incorre...

  • EPSS 16.65%
  • Veröffentlicht 06.01.2012 01:55:01
  • Zuletzt bearbeitet 16.06.2026 23:35:09

The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

  • EPSS 4.99%
  • Veröffentlicht 06.01.2012 01:55:01
  • Zuletzt bearbeitet 16.06.2026 23:36:31

The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.