Vulnerabilities > Openssl > Low

DATE CVE VULNERABILITY TITLE RISK
2007-08-08 CVE-2007-3108 Local Information Disclosure vulnerability in OpenSSL Montgomery Exponentiation Side-Channel
The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys.
local
high complexity
openssl
1.2
2005-02-09 CVE-2004-0975 The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.
local
low complexity
mandrakesoft openssl gentoo
2.1