CVE-2010-4180
- EPSS 9.5%
- Veröffentlicht 06.12.2010 21:05:48
- Zuletzt bearbeitet 16.06.2026 23:24:18
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an uninte...
CVE-2010-3864
- EPSS 22.15%
- Veröffentlicht 17.11.2010 16:00:01
- Zuletzt bearbeitet 16.06.2026 23:23:42
Multiple race conditions in ssl/t1_lib.c in OpenSSL 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, when multi-threading and internal caching are enabled on a TLS server, might allow remote attackers to execute arbitrary code via client data that triggers ...
CVE-2010-2939
- EPSS 9.98%
- Veröffentlicht 17.08.2010 20:00:03
- Zuletzt bearbeitet 16.06.2026 23:21:47
Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service (cras...
CVE-2010-0742
- EPSS 7.83%
- Veröffentlicht 03.06.2010 14:30:01
- Zuletzt bearbeitet 16.06.2026 23:16:45
The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid ...
CVE-2010-1633
- EPSS 2.39%
- Veröffentlicht 03.06.2010 14:30:01
- Zuletzt bearbeitet 16.06.2026 23:18:45
RSA verification recovery in the EVP_PKEY_verify_recover function in OpenSSL 1.x before 1.0.0a, as used by pkeyutl and possibly other applications, returns uninitialized memory upon failure, which might allow context-dependent attackers to bypass int...
- EPSS 20.35%
- Veröffentlicht 26.03.2010 18:30:00
- Zuletzt bearbeitet 16.06.2026 23:16:45
The ssl3_get_record function in ssl/s3_pkt.c in OpenSSL 0.9.8f through 0.9.8m allows remote attackers to cause a denial of service (crash) via a malformed record in a TLS connection that triggers a NULL pointer dereference, related to the minor versi...
- EPSS 6.73%
- Veröffentlicht 05.03.2010 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:11:13
OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent at...
CVE-2010-0433
- EPSS 7.86%
- Veröffentlicht 05.03.2010 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:16:09
The kssl_keytab_is_available function in ssl/kssl.c in OpenSSL before 0.9.8n, when Kerberos is enabled but Kerberos configuration files cannot be opened, does not check a certain return value, which allows remote attackers to cause a denial of servic...
- EPSS 0.54%
- Veröffentlicht 05.03.2010 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:17:09
OpenSSL 0.9.8i on the Gaisler Research LEON3 SoC on the Xilinx Virtex-II Pro FPGA uses a Fixed Width Exponentiation (FWE) algorithm for certain signature calculations, and does not verify the signature before providing it to a caller, which makes it ...
- EPSS 8.94%
- Veröffentlicht 14.01.2010 19:30:00
- Zuletzt bearbeitet 16.06.2026 23:13:30
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to...