Логотип exploitDog
bind:"CVE-2015-1789" OR bind:"CVE-2015-1790" OR bind:"CVE-2015-4000"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2015-1789" OR bind:"CVE-2015-1790" OR bind:"CVE-2015-4000"

Количество 80

Количество 80

suse-cvrf логотип

SUSE-RU-2015:0769-1

почти 11 лет назад

Security update for openssl1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1184-1

почти 11 лет назад

Security update for OpenSSL

EPSS: Низкий
github логотип

GHSA-q289-c6qx-8gxc

около 3 лет назад

The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted length field in ASN1_TIME data, as demonstrated by an attack against a server that supports client authentication with a custom verification callback.

CVSS3: 7.5
EPSS: Низкий
fstec логотип

BDU:2015-11036

около 10 лет назад

Уязвимость библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-1790

около 10 лет назад

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2015-1790

около 10 лет назад

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2015-1790

около 10 лет назад

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2015-1790

около 10 лет назад

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL bef ...

CVSS2: 5
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2016:0640-1

больше 9 лет назад

Security update for libopenssl0_9_8

EPSS: Низкий
ubuntu логотип

CVE-2015-4000

около 10 лет назад

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
EPSS: Критический
redhat логотип

CVE-2015-4000

около 10 лет назад

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
EPSS: Критический
nvd логотип

CVE-2015-4000

около 10 лет назад

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
EPSS: Критический
debian логотип

CVE-2015-4000

около 10 лет назад

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is ena ...

CVSS3: 3.7
EPSS: Критический
github логотип

GHSA-4m2r-fv3j-3fmf

около 3 лет назад

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.

EPSS: Средний
fstec логотип

BDU:2015-11037

около 10 лет назад

Уязвимость библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS2: 5
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2016:2267-1

почти 9 лет назад

Security update for libtcnative-1-0

EPSS: Критический
suse-cvrf логотип

openSUSE-SU-2016:0478-1

больше 9 лет назад

Security update for socat

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2023:0586-1

больше 2 лет назад

Security update for nrpe

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2018:1768-1

около 7 лет назад

Security update for nagios-nrpe

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2016:2385-1

почти 9 лет назад

Security update for libtcnative-1-0

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-RU-2015:0769-1

Security update for openssl1

почти 11 лет назад
suse-cvrf логотип
SUSE-SU-2015:1184-1

Security update for OpenSSL

почти 11 лет назад
github логотип
GHSA-q289-c6qx-8gxc

The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted length field in ASN1_TIME data, as demonstrated by an attack against a server that supports client authentication with a custom verification callback.

CVSS3: 7.5
5%
Низкий
около 3 лет назад
fstec логотип
BDU:2015-11036

Уязвимость библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS2: 4.3
5%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2015-1790

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.

CVSS2: 5
12%
Средний
около 10 лет назад
redhat логотип
CVE-2015-1790

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.

CVSS2: 4.3
12%
Средний
около 10 лет назад
nvd логотип
CVE-2015-1790

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.

CVSS2: 5
12%
Средний
около 10 лет назад
debian логотип
CVE-2015-1790

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL bef ...

CVSS2: 5
12%
Средний
около 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:0640-1

Security update for libopenssl0_9_8

больше 9 лет назад
ubuntu логотип
CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
94%
Критический
около 10 лет назад
redhat логотип
CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
94%
Критический
около 10 лет назад
nvd логотип
CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
94%
Критический
около 10 лет назад
debian логотип
CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is ena ...

CVSS3: 3.7
94%
Критический
около 10 лет назад
github логотип
GHSA-4m2r-fv3j-3fmf

The PKCS7_dataDecodefunction in crypto/pkcs7/pk7_doit.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a PKCS#7 blob that uses ASN.1 encoding and lacks inner EncryptedContent data.

12%
Средний
около 3 лет назад
fstec логотип
BDU:2015-11037

Уязвимость библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS2: 5
12%
Средний
около 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:2267-1

Security update for libtcnative-1-0

94%
Критический
почти 9 лет назад
suse-cvrf логотип
openSUSE-SU-2016:0478-1

Security update for socat

94%
Критический
больше 9 лет назад
suse-cvrf логотип
SUSE-SU-2023:0586-1

Security update for nrpe

94%
Критический
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2018:1768-1

Security update for nagios-nrpe

94%
Критический
около 7 лет назад
suse-cvrf логотип
SUSE-SU-2016:2385-1

Security update for libtcnative-1-0

94%
Критический
почти 9 лет назад

Уязвимостей на страницу