Show filters
63 Total Results
Displaying 61-63 of 63
Sort by:
Attacker Value
Unknown
CVE-2013-6449
Disclosure Date: December 23, 2013 (last updated October 05, 2023)
The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.
0
Attacker Value
Unknown
CVE-2013-0166
Disclosure Date: February 08, 2013 (last updated October 05, 2023)
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
0
Attacker Value
Unknown
CVE-2012-2686
Disclosure Date: February 08, 2013 (last updated October 05, 2023)
crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of service (application crash) via crafted CBC data.
0