|
61
|
7.4
5.8
|
HIGH
Network
|
ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C…
|
CWE-125
Out-of-bounds Read
|
CVE-2021-3712
|
cpe:2.3:a:openssl:openssl:*:*
|
1.0.2 1.1.1
|
|
|
1.0.2za 1.1.1l
|
2026-04-14 19:16
2021-08-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
62
|
9.8
7.5
|
CRITICAL
Network
|
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "o…
|
CWE-120
Classic Buffer Overflow
|
CVE-2021-3711
|
cpe:2.3:a:openssl:openssl:*:*
|
1.1.1
|
|
|
1.1.1l
|
2024-11-21 15:22
2021-08-25
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
63
|
7.4
5.8
|
HIGH
Network
|
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disal…
|
CWE-295
Improper Certificate Validation
|
CVE-2021-3450
|
cpe:2.3:a:openssl:openssl:*:*
|
1.1.1h
|
|
|
1.1.1k
|
2024-11-21 15:21
2021-03-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
64
|
5.9
4.3
|
MEDIUM
Network
|
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where i…
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-3449
|
cpe:2.3:a:openssl:openssl:*:*
|
1.1.1
|
|
|
1.1.1k
|
2024-11-21 15:21
2021-03-26
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
65
|
5.9
4.3
|
MEDIUM
Network
|
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails …
|
CWE-476
NULL Pointer Dereference
|
CVE-2021-23841
|
cpe:2.3:a:openssl:openssl:*:*
|
1.0.2 1.1.1
|
|
|
1.0.2y 1.1.1j
|
2024-11-21 14:51
2021-02-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
66
|
7.5
5.0
|
HIGH
Network
|
Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integ…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2021-23840
|
cpe:2.3:a:openssl:openssl:*:*
|
1.0.2 1.1.1
|
|
|
1.0.2y 1.1.1j
|
2024-11-21 14:51
2021-02-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
67
|
3.7
4.3
|
LOW
Network
|
OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version ro…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2021-23839
|
cpe:2.3:a:openssl:openssl:*:*
|
1.0.2s
|
1.0.2x
|
|
|
2024-11-21 14:51
2021-02-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
68
|
5.9
4.3
|
MEDIUM
Network
|
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares d…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-1971
|
cpe:2.3:a:openssl:openssl:*:*
|
1.0.2 1.1.1
|
|
|
1.0.2x 1.1.1i
|
2024-11-21 14:11
2020-12-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
69
|
3.7
4.3
|
LOW
Network
|
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based cipher…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2020-1968
|
cpe:2.3:a:openssl:openssl:*:*
|
1.0.2
|
1.0.2v
|
|
|
2024-11-21 14:11
2020-09-9
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
70
|
7.5
5.0
|
HIGH
Network
|
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signat…
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-1967
|
cpe:2.3:a:openssl:openssl:*:*
|
1.1.1d
|
1.1.1f
|
|
|
2024-11-21 14:11
2020-04-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|