Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 75

Количество 75

suse-cvrf логотип

SUSE-SU-2023:0307-1

больше 3 лет назад

Security update for openssl1

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0306-1

больше 3 лет назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0305-2

больше 3 лет назад

Security update for openssl-1_0_0

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:0305-1

больше 3 лет назад

Security update for openssl-1_0_0

EPSS: Низкий
ubuntu логотип

CVE-2022-4304

больше 3 лет назад

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
EPSS: Средний
redhat логотип

CVE-2022-4304

больше 3 лет назад

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
EPSS: Средний
nvd логотип

CVE-2022-4304

больше 3 лет назад

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
EPSS: Средний
msrc логотип

CVE-2022-4304

7 месяцев назад

Timing Oracle in RSA Decryption

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2022-4304

больше 3 лет назад

A timing based side channel exists in the OpenSSL RSA Decryption imple ...

CVSS3: 5.9
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2648-1

около 3 лет назад

Security update for openssl-1_1

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2634-1

около 3 лет назад

Security update for openssl

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2633-1

около 3 лет назад

Security update for openssl-1_0_0

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2624-1

около 3 лет назад

Security update for openssl-1_0_0

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2623-1

около 3 лет назад

Security update for openssl-1_1

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:2622-1

около 3 лет назад

Security update for openssl-1_1

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:0584-1

больше 3 лет назад

Security update for openssl

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2023:0581-1

больше 3 лет назад

Security update for compat-openssl098

EPSS: Средний
github логотип

GHSA-p52g-cm5j-mjv4

больше 3 лет назад

openssl-src subject to Timing Oracle in RSA Decryption

CVSS3: 5.9
EPSS: Средний
fstec логотип

BDU:2023-02237

почти 6 лет назад

Уязвимость алгоритмов шифрования PKCS#1 v1.5, RSA-OEAP и RSASVE криптографической библиотеки OpenSSL, позволяющая нарушителю реализовать атаку Блейхенбахера (Bleichenbacher)

CVSS3: 5.9
EPSS: Средний
fstec логотип

BDU:2023-00675

больше 3 лет назад

Уязвимость функции BIO_new_NDEF() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2023:0307-1

Security update for openssl1

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0306-1

Security update for openssl-1_0_0

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0305-2

Security update for openssl-1_0_0

больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0305-1

Security update for openssl-1_0_0

больше 3 лет назад
ubuntu логотип
CVE-2022-4304

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
16%
Средний
больше 3 лет назад
redhat логотип
CVE-2022-4304

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
16%
Средний
больше 3 лет назад
nvd логотип
CVE-2022-4304

A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE. For example, in a TLS connection, RSA is commonly used by a client to send an encrypted pre-master secret to the server. An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them. After a sufficiently large number of messages the attacker could recover the pre-master secret used for the original connection and thus be able to decrypt the application data sent over that connection.

CVSS3: 5.9
16%
Средний
больше 3 лет назад
msrc логотип
CVE-2022-4304

Timing Oracle in RSA Decryption

CVSS3: 5.9
16%
Средний
7 месяцев назад
debian логотип
CVE-2022-4304

A timing based side channel exists in the OpenSSL RSA Decryption imple ...

CVSS3: 5.9
16%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2648-1

Security update for openssl-1_1

16%
Средний
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2634-1

Security update for openssl

16%
Средний
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2633-1

Security update for openssl-1_0_0

16%
Средний
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2624-1

Security update for openssl-1_0_0

16%
Средний
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2623-1

Security update for openssl-1_1

16%
Средний
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:2622-1

Security update for openssl-1_1

16%
Средний
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0584-1

Security update for openssl

16%
Средний
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2023:0581-1

Security update for compat-openssl098

16%
Средний
больше 3 лет назад
github логотип
GHSA-p52g-cm5j-mjv4

openssl-src subject to Timing Oracle in RSA Decryption

CVSS3: 5.9
16%
Средний
больше 3 лет назад
fstec логотип
BDU:2023-02237

Уязвимость алгоритмов шифрования PKCS#1 v1.5, RSA-OEAP и RSASVE криптографической библиотеки OpenSSL, позволяющая нарушителю реализовать атаку Блейхенбахера (Bleichenbacher)

CVSS3: 5.9
16%
Средний
почти 6 лет назад
fstec логотип
BDU:2023-00675

Уязвимость функции BIO_new_NDEF() библиотеки OpenSSL, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.3
4%
Низкий
больше 3 лет назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.