Логотип exploitDog
bind:CVE-2008-3280
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2008-3280

Количество 3

Количество 3

nvd логотип

CVE-2008-3280

больше 4 лет назад

It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166). In combination with the DNS Cache Poisoning issue (CVE-2008-1447) and the fact that almost all SSL/TLS implementations do not consult CRLs (currently an untracked issue), this means that it is impossible to rely on these OPs.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-cq23-cxpr-f49x

почти 4 года назад

It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166). In combination with the DNS Cache Poisoning issue (CVE-2008-1447) and the fact that almost all SSL/TLS implementations do not consult CRLs (currently an untracked issue), this means that it is impossible to rely on these OPs.

EPSS: Низкий
fstec логотип

BDU:2021-05146

больше 4 лет назад

Уязвимость реализации стандарта децентрализованной системы аутентификации OpenID, связанная с ошибками в коде генератора псевдослучайных чисел, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2008-3280

It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166). In combination with the DNS Cache Poisoning issue (CVE-2008-1447) and the fact that almost all SSL/TLS implementations do not consult CRLs (currently an untracked issue), this means that it is impossible to rely on these OPs.

CVSS3: 5.9
6%
Низкий
больше 4 лет назад
github логотип
GHSA-cq23-cxpr-f49x

It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Random Number Generator (CVE-2008-0166). In combination with the DNS Cache Poisoning issue (CVE-2008-1447) and the fact that almost all SSL/TLS implementations do not consult CRLs (currently an untracked issue), this means that it is impossible to rely on these OPs.

6%
Низкий
почти 4 года назад
fstec логотип
BDU:2021-05146

Уязвимость реализации стандарта децентрализованной системы аутентификации OpenID, связанная с ошибками в коде генератора псевдослучайных чисел, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.9
6%
Низкий
больше 4 лет назад

Уязвимостей на страницу