|
81
|
5.5
2.1
|
MEDIUM
Local
|
A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.
|
-
|
CVE-2016-7056
|
cpe:2.3:a:openssl:openssl:*:*
|
|
1.0.1u
|
|
|
2024-11-21 11:57
2018-09-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
82
|
7.5
5.0
|
HIGH
Network
|
During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long pe…
|
CWE-320
Key Management Errors
|
CVE-2018-0732
|
cpe:2.3:a:openssl:openssl:*:*
|
1.1.0 1.0.2
|
1.1.0h 1.0.2o
|
|
|
2024-11-21 12:38
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
83
|
5.9
4.3
|
MEDIUM
Network
|
The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key gen…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-0737
|
cpe:2.3:a:openssl:openssl:*:*
|
1.0.2b 1.1.0
|
1.0.2o 1.1.0h
|
|
|
2024-11-21 12:38
2018-04-17
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
84
|
6.5
4.3
|
MEDIUM
Network
|
Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of …
|
CWE-674
Uncontrolled Recursion
|
CVE-2018-0739
|
cpe:2.3:a:openssl:openssl:*:*
|
1.0.2b 1.1.0
|
1.0.2n 1.1.0g
|
|
|
2024-11-21 12:38
2018-03-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
85
|
5.9
4.3
|
MEDIUM
Network
|
Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that wou…
|
NVD-CWE-noinfo
|
CVE-2018-0733
|
cpe:2.3:a:openssl:openssl:*:*
|
1.1.0
|
1.1.0g
|
|
|
2024-11-21 12:38
2018-03-28
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
86
|
5.9
4.3
|
MEDIUM
Network
|
There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA…
|
CWE-200
Information Exposure
|
CVE-2017-3738
|
cpe:2.3:a:openssl:openssl:1.1.0g:* cpe:2.3:a:openssl:openssl:1.1.0f:* cpe:2.3:a:openssl:openssl:1.1.0e:* cpe:2…
|
|
|
|
|
2024-11-21 12:26
2017-12-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
87
|
5.9
4.3
|
MEDIUM
Network
|
OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into the error state and w…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-3737
|
cpe:2.3:a:openssl:openssl:1.0.2m:* cpe:2.3:a:openssl:openssl:1.0.2l:* cpe:2.3:a:openssl:openssl:1.0.2k:* cpe:2…
|
|
|
|
|
2024-11-21 12:26
2017-12-8
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
88
|
7.5
5.0
|
HIGH
Network
|
A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote…
|
-
|
CVE-2016-8610
|
cpe:2.3:a:openssl:openssl:1.1.0:* cpe:2.3:a:openssl:openssl:1.0.1:* cpe:2.3:a:openssl:openssl:0.9.8:* cpe:2.3:…
|
1.0.2
|
1.0.2h
|
|
|
2024-11-21 11:59
2017-11-14
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
89
|
6.5
4.0
|
MEDIUM
Network
|
There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL before 1.0.2m and 1.1.0 before 1.1.0g. No EC algorithms are affected. Analysis suggests that attacks against RS…
|
CWE-200
Information Exposure
|
CVE-2017-3736
|
cpe:2.3:a:openssl:openssl:*:*
|
1.1.0 1.0.2
|
|
|
1.1.0g 1.0.2m
|
2024-11-21 12:26
2017-11-3
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
90
|
5.3
5.0
|
MEDIUM
Network
|
While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been pres…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-3735
|
cpe:2.3:a:openssl:openssl:1.1.0f:* cpe:2.3:a:openssl:openssl:1.1.0e:* cpe:2.3:a:openssl:openssl:1.1.0d:* cpe:2…
|
|
|
|
|
2024-11-21 12:26
2017-08-29
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|