CVE-2018-11069
- EPSS 0.28%
- Published 11.09.2018 19:29:01
- Last modified 21.11.2024 03:42:37
RSA BSAFE SSL-J versions prior to 6.2.4 contain a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.
CVE-2016-0887
- EPSS 0.94%
- Published 12.04.2016 23:59:31
- Last modified 12.04.2025 10:46:40
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x and 4.1.x before 4.1.5, RSA BSAFE Crypto-C Micro Edition (CCME) 4.0.x and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2.1, RSA BSAFE SSL-J before 6.2.1, and RSA BSAFE SSL-C before 2.8.9 allow remote a...
CVE-2015-0534
- EPSS 0.95%
- Published 20.08.2015 10:59:01
- Last modified 12.04.2025 10:46:40
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA BSAFE SSL-C 2.8.9 and earlier do not enforce certain constraints on certificate data, which allows r...
CVE-2014-4630
- EPSS 0.19%
- Published 30.12.2014 15:59:00
- Last modified 12.04.2025 10:46:40
EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.6 and RSA BSAFE SSL-J before 6.1.4 do not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which allows man-in-the-middle attackers to o...
- EPSS 0.24%
- Published 18.02.2014 00:55:05
- Last modified 11.04.2025 00:51:21
The SSLEngine API implementation in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to trigger the selection of a weak cipher suite by using the wrap method during a certain incomplete-handshake state.
- EPSS 0.18%
- Published 18.02.2014 00:55:05
- Last modified 11.04.2025 00:51:21
The (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 make it easier for remote attackers to bypass intended cryptographic protection mechanisms by triggering application-data processing during the TLS handshake...
- EPSS 0.47%
- Published 18.02.2014 00:55:05
- Last modified 11.04.2025 00:51:21
The SSLSocket implementation in the (1) JSAFE and (2) JSSE APIs in EMC RSA BSAFE SSL-J 5.x before 5.1.3 and 6.x before 6.0.2 allows remote attackers to cause a denial of service (memory consumption) by triggering application-data processing during th...
- EPSS 0.67%
- Published 23.11.2004 05:00:00
- Last modified 03.04.2025 01:03:51
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a ...
- EPSS 2.27%
- Published 23.11.2004 05:00:00
- Last modified 03.04.2025 01:03:51
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
CVE-2004-0079
- EPSS 2.06%
- Published 23.11.2004 05:00:00
- Last modified 03.04.2025 01:03:51
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.