Vulnerabilities > Openssl > Openssl > 1.0.0e

DATE CVE VULNERABILITY TITLE RISK
2012-01-06 CVE-2011-4577 Resource Management Errors vulnerability in Openssl
OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, allows remote attackers to cause a denial of service (assertion failure) via an X.509 certificate containing certificate-extension data associated with (1) IP address blocks or (2) Autonomous System (AS) identifiers.
network
openssl CWE-399
4.3
2012-01-06 CVE-2011-4576 Cryptographic Issues vulnerability in Openssl
The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly initialize data structures for block cipher padding, which might allow remote attackers to obtain sensitive information by decrypting the padding data sent by an SSL peer.
network
low complexity
openssl CWE-310
5.0
2012-01-06 CVE-2011-4108 Cryptographic Issues vulnerability in Openssl
The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.
network
openssl CWE-310
4.3