Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 51

Количество 51

fstec логотип

BDU:2022-01315

больше 4 лет назад

Уязвимость функции BN_mod_sqrt() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Высокий
redos логотип

ROS-20220318-02

больше 4 лет назад

Уязвимость библиотеки OpenSSL

EPSS: Высокий
altlinux логотип

ALT-PU-2022-2174

около 4 лет назад

ALT-PU-2022-2174: package `mysql-connector-odbc` update to version 8.0.29-alt1

CVSS3: 7.5
EPSS: Высокий
altlinux логотип

ALT-PU-2022-2167

около 4 лет назад

ALT-PU-2022-2167: package `mysql-connector-odbc` update to version 8.0.29-alt1

CVSS3: 7.5
EPSS: Высокий
altlinux логотип

ALT-PU-2022-1489

больше 4 лет назад

ALT-PU-2022-1489: package `openssl1.1` update to version 1.1.1n-alt1

CVSS3: 7.5
EPSS: Высокий
altlinux логотип

ALT-PU-2022-1515

больше 4 лет назад

ALT-PU-2022-1515: package `openssl1.1` update to version 1.1.1n-alt1

CVSS3: 7.5
EPSS: Низкий
altlinux логотип

ALT-PU-2022-1799

больше 4 лет назад

ALT-PU-2022-1799: package `node` update to version 14.19.1-alt1

CVSS3: 8.2
EPSS: Низкий
altlinux логотип

ALT-PU-2022-1760

больше 4 лет назад

ALT-PU-2022-1760: package `node` update to version 16.14.2-alt1

CVSS3: 8.2
EPSS: Низкий
altlinux логотип

ALT-PU-2023-1461

больше 3 лет назад

ALT-PU-2023-1461: package `node` update to version 16.18.1-alt1

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2022-0778

больше 4 лет назад

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities...

CVSS3: 7.5
EPSS: Высокий
redhat логотип

CVE-2022-0778

больше 4 лет назад

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities...

CVSS3: 7.5
EPSS: Высокий
nvd логотип

CVE-2022-0778

больше 4 лет назад

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities pa

CVSS3: 7.5
EPSS: Высокий
msrc логотип

CVE-2022-0778

больше 4 лет назад

CVSS3: 7.5
EPSS: Высокий
debian логотип

CVE-2022-0778

больше 4 лет назад

The BN_mod_sqrt() function, which computes a modular square root, cont ...

CVSS3: 7.5
EPSS: Высокий
suse-cvrf логотип

openSUSE-SU-2022:0856-1

больше 4 лет назад

Security update for openssl-1_0_0

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:14916-1

больше 4 лет назад

Security update for openssl1

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:14915-1

больше 4 лет назад

Security update for openssl

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:0935-1

больше 4 лет назад

Security update for nodejs12

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:0860-1

больше 4 лет назад

Security update for openssl-1_1

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:0859-1

больше 4 лет назад

Security update for compat-openssl098

EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2022-01315

Уязвимость функции BN_mod_sqrt() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
73%
Высокий
больше 4 лет назад
redos логотип
ROS-20220318-02

Уязвимость библиотеки OpenSSL

73%
Высокий
больше 4 лет назад
altlinux логотип
ALT-PU-2022-2174

ALT-PU-2022-2174: package `mysql-connector-odbc` update to version 8.0.29-alt1

CVSS3: 7.5
73%
Высокий
около 4 лет назад
altlinux логотип
ALT-PU-2022-2167

ALT-PU-2022-2167: package `mysql-connector-odbc` update to version 8.0.29-alt1

CVSS3: 7.5
73%
Высокий
около 4 лет назад
altlinux логотип
ALT-PU-2022-1489

ALT-PU-2022-1489: package `openssl1.1` update to version 1.1.1n-alt1

CVSS3: 7.5
73%
Высокий
больше 4 лет назад
altlinux логотип
ALT-PU-2022-1515

ALT-PU-2022-1515: package `openssl1.1` update to version 1.1.1n-alt1

CVSS3: 7.5
больше 4 лет назад
altlinux логотип
ALT-PU-2022-1799

ALT-PU-2022-1799: package `node` update to version 14.19.1-alt1

CVSS3: 8.2
больше 4 лет назад
altlinux логотип
ALT-PU-2022-1760

ALT-PU-2022-1760: package `node` update to version 16.14.2-alt1

CVSS3: 8.2
больше 4 лет назад
altlinux логотип
ALT-PU-2023-1461

ALT-PU-2023-1461: package `node` update to version 16.18.1-alt1

CVSS3: 9.8
больше 3 лет назад
ubuntu логотип
CVE-2022-0778

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities...

CVSS3: 7.5
73%
Высокий
больше 4 лет назад
redhat логотип
CVE-2022-0778

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities...

CVSS3: 7.5
73%
Высокий
больше 4 лет назад
nvd логотип
CVE-2022-0778

The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded in compressed form. It is possible to trigger the infinite loop by crafting a certificate that has invalid explicit curve parameters. Since certificate parsing happens prior to verification of the certificate signature, any process that parses an externally supplied certificate may thus be subject to a denial of service attack. The infinite loop can also be reached when parsing crafted private keys as they can contain explicit elliptic curve parameters. Thus vulnerable situations include: - TLS clients consuming server certificates - TLS servers consuming client certificates - Hosting providers taking certificates or private keys from customers - Certificate authorities pa

CVSS3: 7.5
73%
Высокий
больше 4 лет назад
msrc логотип
CVSS3: 7.5
73%
Высокий
больше 4 лет назад
debian логотип
CVE-2022-0778

The BN_mod_sqrt() function, which computes a modular square root, cont ...

CVSS3: 7.5
73%
Высокий
больше 4 лет назад
suse-cvrf логотип
openSUSE-SU-2022:0856-1

Security update for openssl-1_0_0

73%
Высокий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:14916-1

Security update for openssl1

73%
Высокий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:14915-1

Security update for openssl

73%
Высокий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:0935-1

Security update for nodejs12

73%
Высокий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:0860-1

Security update for openssl-1_1

73%
Высокий
больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2022:0859-1

Security update for compat-openssl098

73%
Высокий
больше 4 лет назад

Уязвимостей на страницу