from 0, < 1.0.1g-1
from 0, < 1.0.1e-2+deb7u5
CRITICAL9.8pound - security update
from 0, < 0.9.8k-6
CRITICAL9.8pound - security update
from 0, < 0.9.8g-15+lenny11
CRITICAL9.8Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of…
from 0, < 1.0.2i-1
CRITICAL9.8The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote att…
from 0, < 1.0.2i-1
CRITICAL9.8openssl - security update
from 0, < 1.0.2i-1
CRITICAL9.8openssl - security update
from 0, < 1.0.1t-1+deb7u1
CRITICAL9.8openssl - security update
from 0, < 1.0.1t-1+deb8u4
CRITICAL9.8The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a deni…
from 0, < 1.0.2c-1
CRITICAL9.8The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memo…
from 0, < 1.0.2g-1
CRITICAL9.8The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, wh…
from 0, < 1.0.2g-1
CRITICAL9.8Double free vulnerability in the dsa_priv_decode function in crypto/dsa/dsa_ameth.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g…
from 0, < 1.0.2g-1
CRITICAL9.8Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code…
from 0, < 0.9.7c
CRITICAL9.1Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer may cause a crash or…
from 0, < 1.1.1w-0+deb11u2
HIGH7.5Issue summary: When a partial-chain certificate verification is enabled together with OCSP response checking for the whole chain, a NULL de…
from 0, < 3.6.3-1
HIGH7.5Issue summary: Applications using AES-CFB128 encryption or decryption on systems with AVX-512 and VAES support can trigger an out-of-bounds…
from 0, < 3.6.2-1
HIGH7.5openssl - security update
from 0, < 1.1.1w-0+deb11u4
HIGH7.5openssl - security update
from 0, < 1.1.1w-0+deb11u4
HIGH7.5openssl - security update
from 0, < 3.0.17-1~deb12u3
HIGH7.5Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situatio…
from 0, < 1.1.1w-0+deb11u2
HIGH7.5A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined process…
from 0, < 1.0.2j-1
HIGH7.5During a renegotiation handshake if the Encrypt-Then-Mac extension is negotiated where it was not in the original handshake (or vice-versa)…
from 0, < 1.1.0e-1
HIGH7.5If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that ser…
from 0, < 1.1.0d-1
HIGH7.5In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the c…
from 0, < 1.1.0d-1
HIGH7.5In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger…
from 0, < 1.1.0c-1
HIGH7.5In OpenSSL 1.1.0 before 1.1.0c, applications parsing invalid CMS structures can crash with a NULL pointer dereference.
from 0, < 1.1.0c-1
HIGH7.5crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application cra…
from 0, < 1.0.2j-1
HIGH7.5Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a…
from 0, < 1.0.2i-1
HIGH7.5The tls_decrypt_ticket function in ssl/t1_lib.c in OpenSSL before 1.1.0 does not consider the HMAC size during validation of the ticket len…
from 0, < 1.0.2i-1
HIGH7.5The Anti-Replay feature in the DTLS implementation in OpenSSL before 1.1.0 mishandles early use of a new epoch number in conjunction with a…
from 0, < 1.0.2i-1
HIGH7.5The DTLS implementation in OpenSSL before 1.1.0 does not properly restrict the lifetime of queue entries associated with unused out-of-orde…
from 0, < 1.0.2i-1
HIGH7.5The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in Open…
from 0, < 1.0.2i-1
HIGH7.5The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h a…
from 0, < 1.0.2h-1
HIGH7.5Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote a…
from 0, < 1.0.2h-1
HIGH7.5openssl - security update
from 0, < 1.0.2h-1
HIGH7.5openssl - security update
from 0, < 1.0.1e-2+deb7u21
HIGH7.5openssl - security update
from 0, < 1.0.1k-3+deb8u5
HIGH7.5crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it ea…
from 0, < 0.9.6-1
HIGH7.5Memory leak in the SRP_VBASE_get_by_user implementation in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allows remote attackers to c…
from 0, < 1.0.2g-1
HIGH7.5Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap…
from 0, < 1.0.2g-1
HIGH7.5openssl - security update
from 0, < 1.0.2e-1
HIGH7.5openssl - security update
from 0, < 1.0.1e-2+deb7u18
HIGH7.5The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by t…
from 0, < 1.0.2e-1
HIGH7.5The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before…
from 0, < 1.0.2b-1
HIGH7.5OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable…
from 0, < 0.9.8g-9
HIGH7.5The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorith…
from 0, < 0.9.8-1
HIGH7.5openssl - several vulnerabilities
from 0, < 0.9.7d-1
HIGH7.5openssl - several vulnerabilities
from 0, < 0.9.6c-2.woody.6
HIGH7.4OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, wh…
from 0, < 1.0.1h-1
MEDIUM6.5Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate.
from 0, < 3.5.0-2
MEDIUM6.5The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic…
from 0, < 1.0.2d-1
MEDIUM5.9Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment v…
from 0, < 3.0.17-1~deb12u3
MEDIUM5.9Issue summary: Checking excessively long invalid RSA public keys may take a long time.
from 0, < 3.0.13-1~deb12u1
MEDIUM5.9Issue summary: Some non-default TLS server configurations can cause unbounded memory growth when processing TLSv1.3 sessions Impact summary…
from 0, < 1.1.1w-0+deb11u2
MEDIUM5.9openssl - security update
from 0, < 1.1.1k-1+deb11u2
MEDIUM5.9openssl - security update
from 0, < 1.1.1d-0+deb10u8
MEDIUM5.9There is an overflow bug in the AVX2 Montgomery multiplication procedure used in exponentiation with 1024-bit moduli.
from 0, < 1.1.0h-1
MEDIUM5.9openssl1.0 - security update
from 0, < 1.1.0b-2
MEDIUM5.9There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d.
from 0, < 1.1.0d-1
MEDIUM5.9The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-b…
from 0, < 1.0.2i-1
MEDIUM5.9The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding che…
from 0, < 1.0.2h-1
MEDIUM5.9An oracle protection mechanism in the get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.…
from 0, < 1.0.0c-2
MEDIUM5.9The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.…
from 0, < 1.0.0c-2
MEDIUM5.9The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify m…
from 0, < 1.0.0c-2
MEDIUM5.9openssl - security update
from 0, < 1.0.0c-2
MEDIUM5.9openssl - security update
from 0, < 0.9.8o-4squeeze23
MEDIUM5.9icedove - security update
from 0, < 1.0.1f-1
MEDIUM5.9icedove - security update
from 0, < 1.0.1e-2+deb7u19
MEDIUM5.5openssl - security update
from 0, < 1.0.2a-1
MEDIUM5.5openssl - security update
from 0, < 1.0.1t-1+deb7u2
MEDIUM5.5openssl - security update
from 0, < 1.0.1t-1+deb8u6
MEDIUM5.5The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations…
from 0, < 1.0.2i-1
MEDIUM5.3OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of…
from 0
MEDIUM5.3Issue summary: Checking excessively long DSA keys or parameters may be very slow.
from 0, < 3.0.14-1~deb12u1
MEDIUM5.3openssl - security update
from 0, < 1.1.1v-0~deb11u1
MEDIUM5.3openssl - security update
from 0, < 1.1.1n-0+deb10u6
MEDIUM5.3openssl - security update
from 0, < 1.1.0g-1
MEDIUM5.3openssl - security update
from 0, < 1.0.1t-1+deb7u3
MEDIUM5.3openssl - security update
from 0, < 1.0.1t-1+deb8u7
MEDIUM5.3openssl - security update
from 0, < 1.0.2e-1
MEDIUM5.3openssl - security update
from 0, < 0.9.8o-4squeeze22
MEDIUM5.1openssl - security update
from 0, < 1.0.2g-1
MEDIUM5.1openssl - security update
from 0, < 1.0.1e-2+deb7u20
MEDIUM5.0Issue summary: A malicious server can exploit TLS OCSP stapling by delivering a crafted response through the status_request extension, trig…
from 0, < 3.6.3-1
MEDIUM4.3Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-…
from 0, < 1.1.1w-0+deb11u2
MEDIUM4.1openssl - security update
from 0, < 1.1.1w-0+deb11u3
MEDIUM4.1openssl - security update
from 0, < 1.1.1w-0+deb11u3
LOW3.7Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly checked for the subgroup…
from 0, < 3.0.20-1~deb12u2
LOW3.7openssl1.0 - security update
from 0, < 1.1.0c-1
LOW3.7The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for…
from 0, < 1.0.2f-2
LOW3.7nss - security update
from 0, < 1.0.2b-1
LOW3.4lighttpd - security update
from 0, < 1.0.1j-1
—ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes t…
from 0, < 1.0.2d-1
—The ssl3_get_key_exchange function in ssl/s3_clnt.c in OpenSSL 1.0.2 before 1.0.2e allows remote servers to cause a denial of service (segm…
from 0, < 1.0.2e-1
—The do_free_upto function in crypto/cms/cms_smime.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1…
from 0, < 1.0.2b-1
—Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.…
from 0, < 1.0.2b-1
—The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 befo…
from 0, < 1.0.2b-1
—The BN_GF2m_mod_inv function in crypto/bn/bn_gf2m.c in OpenSSL before 0.9.8s, 1.0.0 before 1.0.0e, 1.0.1 before 1.0.1n, and 1.0.2 before 1.…
from 0, < 1.0.2b-1
—openssl - security update
from 0, < 1.0.1h-1