Логотип exploitDog
bind:"CVE-2013-6449" OR bind:"CVE-2013-6450" OR bind:"CVE-2013-4353"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2013-6449" OR bind:"CVE-2013-6450" OR bind:"CVE-2013-4353"

Количество 19

Количество 19

oracle-oval логотип

ELSA-2014-0015

около 12 лет назад

ELSA-2014-0015: openssl security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2015-01314

около 12 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить целостность и доступность защищаемой информации

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2013-6449

около 12 лет назад

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2013-6449

около 12 лет назад

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2013-6449

около 12 лет назад

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2013-6449

около 12 лет назад

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0. ...

CVSS2: 4.3
EPSS: Средний
fstec логотип

BDU:2015-09775

около 11 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 7.5
EPSS: Низкий
github логотип

GHSA-h84w-39m4-37j6

больше 3 лет назад

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

EPSS: Средний
ubuntu логотип

CVE-2013-4353

около 12 лет назад

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2013-4353

около 12 лет назад

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2013-4353

около 12 лет назад

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2013-4353

около 12 лет назад

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1. ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2013-6450

около 12 лет назад

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2013-6450

около 12 лет назад

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-6450

около 12 лет назад

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2013-6450

около 12 лет назад

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l ...

CVSS2: 5.8
EPSS: Низкий
github логотип

GHSA-3r93-c4x2-hj85

больше 3 лет назад

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

EPSS: Средний
fstec логотип

BDU:2015-09745

почти 12 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-3qp2-qh33-29hx

больше 3 лет назад

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2014-0015

ELSA-2014-0015: openssl security update (IMPORTANT)

около 12 лет назад
fstec логотип
BDU:2015-01314

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить целостность и доступность защищаемой информации

CVSS2: 5.8
около 12 лет назад
ubuntu логотип
CVE-2013-6449

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 4.3
21%
Средний
около 12 лет назад
redhat логотип
CVE-2013-6449

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 5
21%
Средний
около 12 лет назад
nvd логотип
CVE-2013-6449

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 4.3
21%
Средний
около 12 лет назад
debian логотип
CVE-2013-6449

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0. ...

CVSS2: 4.3
21%
Средний
около 12 лет назад
fstec логотип
BDU:2015-09775

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 7.5
около 11 лет назад
github логотип
GHSA-h84w-39m4-37j6

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

21%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2013-4353

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
14%
Средний
около 12 лет назад
redhat логотип
CVE-2013-4353

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
14%
Средний
около 12 лет назад
nvd логотип
CVE-2013-4353

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
14%
Средний
около 12 лет назад
debian логотип
CVE-2013-4353

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1. ...

CVSS2: 4.3
14%
Средний
около 12 лет назад
ubuntu логотип
CVE-2013-6450

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5.8
7%
Низкий
около 12 лет назад
redhat логотип
CVE-2013-6450

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5
7%
Низкий
около 12 лет назад
nvd логотип
CVE-2013-6450

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5.8
7%
Низкий
около 12 лет назад
debian логотип
CVE-2013-6450

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l ...

CVSS2: 5.8
7%
Низкий
около 12 лет назад
github логотип
GHSA-3r93-c4x2-hj85

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

14%
Средний
больше 3 лет назад
fstec логотип
BDU:2015-09745

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 4.3
14%
Средний
почти 12 лет назад
github логотип
GHSA-3qp2-qh33-29hx

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

7%
Низкий
больше 3 лет назад

Уязвимостей на страницу