CVE-2012-2333
- EPSS 28.15%
- Veröffentlicht 14.05.2012 22:55:03
- Zuletzt bearbeitet 16.06.2026 23:41:22
Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified...
CVE-2012-2131
- EPSS 17%
- Veröffentlicht 24.04.2012 20:55:02
- Zuletzt bearbeitet 16.06.2026 23:41:03
Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER dat...
CVE-2012-2110
- EPSS 48.3%
- Veröffentlicht 19.04.2012 17:55:01
- Zuletzt bearbeitet 16.06.2026 23:41:00
The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a de...
- EPSS 6.77%
- Veröffentlicht 15.03.2012 17:55:00
- Zuletzt bearbeitet 16.06.2026 23:39:10
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulne...
- EPSS 12.93%
- Veröffentlicht 13.03.2012 03:12:26
- Zuletzt bearbeitet 16.06.2026 23:38:27
The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict certain oracle behavior, which makes it easier for context-dependent attackers to decrypt data via a Millio...
- EPSS 6.99%
- Veröffentlicht 29.02.2012 11:55:04
- Zuletzt bearbeitet 16.06.2026 22:34:39
The mime_hdr_cmp function in crypto/asn1/asn_mime.c in OpenSSL 0.9.8t and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message.
CVE-2011-4354
- EPSS 4.04%
- Veröffentlicht 27.01.2012 00:55:01
- Zuletzt bearbeitet 16.06.2026 23:34:49
crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 ...
- EPSS 13.86%
- Veröffentlicht 19.01.2012 19:55:01
- Zuletzt bearbeitet 16.06.2026 23:36:34
OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an out-of-bounds read. NOTE: this vulnerability exists because of an incorre...
- EPSS 16.65%
- Veröffentlicht 06.01.2012 01:55:01
- Zuletzt bearbeitet 16.06.2026 23:35:09
The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
- EPSS 4.99%
- Veröffentlicht 06.01.2012 01:55:01
- Zuletzt bearbeitet 16.06.2026 23:36:31
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.