Show filters
47 Total Results
Displaying 11-20 of 47
Sort by:
Attacker Value
Unknown

CVE-2011-4619

Disclosure Date: January 06, 2012 (last updated October 04, 2023)
The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-4108

Disclosure Date: January 06, 2012 (last updated October 04, 2023)
The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.
0
Attacker Value
Unknown

CVE-2011-4576

Disclosure Date: January 06, 2012 (last updated October 04, 2023)
The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly initialize data structures for block cipher padding, which might allow remote attackers to obtain sensitive information by decrypting the padding data sent by an SSL peer.
0
Attacker Value
Unknown

CVE-2012-0027

Disclosure Date: January 06, 2012 (last updated October 04, 2023)
The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.
0
Attacker Value
Unknown

CVE-2011-4577

Disclosure Date: January 06, 2012 (last updated October 04, 2023)
OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, allows remote attackers to cause a denial of service (assertion failure) via an X.509 certificate containing certificate-extension data associated with (1) IP address blocks or (2) Autonomous System (AS) identifiers.
0
Attacker Value
Unknown

CVE-2011-1945

Disclosure Date: May 31, 2011 (last updated October 04, 2023)
The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation.
0
Attacker Value
Unknown

CVE-2008-7270

Disclosure Date: December 06, 2010 (last updated October 04, 2023)
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
0
Attacker Value
Unknown

CVE-2010-4252

Disclosure Date: December 06, 2010 (last updated October 04, 2023)
OpenSSL before 1.0.0c, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol.
0
Attacker Value
Unknown

CVE-2010-2939

Disclosure Date: August 17, 2010 (last updated November 08, 2023)
Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted private key with an invalid prime. NOTE: some sources refer to this as a use-after-free issue.
0
Attacker Value
Unknown

CVE-2009-4355

Disclosure Date: January 14, 2010 (last updated October 04, 2023)
Memory leak in the zlib_stateful_finish function in crypto/comp/c_zlib.c in OpenSSL 0.9.8l and earlier and 1.0.0 Beta through Beta 4 allows remote attackers to cause a denial of service (memory consumption) via vectors that trigger incorrect calls to the CRYPTO_cleanup_all_ex_data function, as demonstrated by use of SSLv3 and PHP with the Apache HTTP Server, a related issue to CVE-2008-1678.
0