Логотип exploitDog
bind:"CVE-2013-6449" OR bind:"CVE-2013-6450" OR bind:"CVE-2013-4353"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2013-6449" OR bind:"CVE-2013-6450" OR bind:"CVE-2013-4353"

Количество 19

Количество 19

oracle-oval логотип

ELSA-2014-0015

больше 11 лет назад

ELSA-2014-0015: openssl security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2015-01314

больше 11 лет назад

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить целостность и доступность защищаемой информации

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2013-6449

больше 11 лет назад

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2013-6449

больше 11 лет назад

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2013-6449

больше 11 лет назад

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2013-6449

больше 11 лет назад

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0. ...

CVSS2: 4.3
EPSS: Средний
fstec логотип

BDU:2015-09775

больше 10 лет назад

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 7.5
EPSS: Низкий
github логотип

GHSA-h84w-39m4-37j6

больше 3 лет назад

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

EPSS: Средний
ubuntu логотип

CVE-2013-4353

больше 11 лет назад

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
EPSS: Средний
redhat логотип

CVE-2013-4353

больше 11 лет назад

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2013-4353

больше 11 лет назад

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2013-4353

больше 11 лет назад

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1. ...

CVSS2: 4.3
EPSS: Средний
ubuntu логотип

CVE-2013-6450

больше 11 лет назад

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5.8
EPSS: Средний
redhat логотип

CVE-2013-6450

больше 11 лет назад

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2013-6450

больше 11 лет назад

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5.8
EPSS: Средний
debian логотип

CVE-2013-6450

больше 11 лет назад

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l ...

CVSS2: 5.8
EPSS: Средний
github логотип

GHSA-3r93-c4x2-hj85

около 3 лет назад

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

EPSS: Средний
fstec логотип

BDU:2015-09745

больше 11 лет назад

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 4.3
EPSS: Средний
github логотип

GHSA-3qp2-qh33-29hx

больше 3 лет назад

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2014-0015

ELSA-2014-0015: openssl security update (IMPORTANT)

больше 11 лет назад
fstec логотип
BDU:2015-01314

Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить целостность и доступность защищаемой информации

CVSS2: 5.8
больше 11 лет назад
ubuntu логотип
CVE-2013-6449

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 4.3
17%
Средний
больше 11 лет назад
redhat логотип
CVE-2013-6449

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 5
17%
Средний
больше 11 лет назад
nvd логотип
CVE-2013-6449

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

CVSS2: 4.3
17%
Средний
больше 11 лет назад
debian логотип
CVE-2013-6449

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0. ...

CVSS2: 4.3
17%
Средний
больше 11 лет назад
fstec логотип
BDU:2015-09775

Уязвимости операционной системы Gentoo Linux, позволяющие удаленному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

CVSS2: 7.5
больше 10 лет назад
github логотип
GHSA-h84w-39m4-37j6

The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client.

17%
Средний
больше 3 лет назад
ubuntu логотип
CVE-2013-4353

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
13%
Средний
больше 11 лет назад
redhat логотип
CVE-2013-4353

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
13%
Средний
больше 11 лет назад
nvd логотип
CVE-2013-4353

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

CVSS2: 4.3
13%
Средний
больше 11 лет назад
debian логотип
CVE-2013-4353

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1. ...

CVSS2: 4.3
13%
Средний
больше 11 лет назад
ubuntu логотип
CVE-2013-6450

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5.8
28%
Средний
больше 11 лет назад
redhat логотип
CVE-2013-6450

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5
28%
Средний
больше 11 лет назад
nvd логотип
CVE-2013-6450

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

CVSS2: 5.8
28%
Средний
больше 11 лет назад
debian логотип
CVE-2013-6450

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l ...

CVSS2: 5.8
28%
Средний
больше 11 лет назад
github логотип
GHSA-3r93-c4x2-hj85

The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.

13%
Средний
около 3 лет назад
fstec логотип
BDU:2015-09745

Уязвимость операционной системы Gentoo Linux, позволяющая удаленному злоумышленнику нарушить доступность защищаемой информации

CVSS2: 4.3
13%
Средний
больше 11 лет назад
github логотип
GHSA-3qp2-qh33-29hx

The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_both.c and ssl/t1_enc.c.

28%
Средний
больше 3 лет назад

Уязвимостей на страницу