Vulnerabilities > Openssl > Openssl > 0.9.8c

DATE CVE VULNERABILITY TITLE RISK
2009-03-27 CVE-2009-0590 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
network
low complexity
openssl debian CWE-119
5.0
2009-01-07 CVE-2008-5077 Improper Input Validation vulnerability in Openssl
OpenSSL 0.9.8i and earlier does not properly check the return value from the EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys.
network
openssl CWE-20
5.8
2007-10-13 CVE-2007-4995 Numeric Errors vulnerability in Openssl
Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors.
network
openssl CWE-189
critical
9.3
2007-09-27 CVE-2007-5135 Numeric Errors vulnerability in Openssl
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow.
network
openssl CWE-189
6.8
2007-08-08 CVE-2007-3108 Local Information Disclosure vulnerability in OpenSSL Montgomery Exponentiation Side-Channel
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
local
high complexity
openssl
1.2
2006-09-28 CVE-2006-4343 Null Pointer Dereference vulnerability in multiple products
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.
4.3
2006-09-28 CVE-2006-3738 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Openssl
Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspecified impact and remote attack vectors involving a long list of ciphers.
network
low complexity
openssl CWE-119
critical
10.0
2006-09-28 CVE-2006-2940 Resource Management Errors vulnerability in Openssl
OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification.
network
low complexity
openssl CWE-399
7.8
2006-09-28 CVE-2006-2937 Resource Management Errors vulnerability in Openssl
OpenSSL 0.9.7 before 0.9.7l and 0.9.8 before 0.9.8d allows remote attackers to cause a denial of service (infinite loop and memory consumption) via malformed ASN.1 structures that trigger an improperly handled error condition.
network
low complexity
openssl CWE-399
7.8