cbcvebase.

Debian OpenSSL vulnerabilities

249 known vulnerabilities affecting debian/openssl.

Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2

Vulnerabilities

Page 1 of 13
CVE-2014-0160P1HIGHCVSS 7.5KEVPoCfixed in openssl 1.0.1g-1 (bookworm)2014
CVE-2014-0160 [HIGH] CVE-2014-0160: openssl - The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not p... The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug. Scope: loca
debian
CVE-2009-3555P1MEDIUMCVSS 5.8ExploitedPoCfixed in apache2 2.2.14-2 (bookworm)2009
CVE-2009-3555 [MEDIUM] CVE-2009-3555: apache2 - The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Micr... The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate reneg
debian
CVE-2014-0224P1HIGHCVSS 7.4ExploitedPoCfixed in openssl 1.0.1h-1 (bookworm)2014
CVE-2014-0224 [HIGH] CVE-2014-0224: openssl - OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not pr... OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the
debian
CVE-2014-0195P2MEDIUMCVSS 6.8PoCfixed in openssl 1.0.1h-1 (bookworm)2014
CVE-2014-0195 [MEDIUM] CVE-2014-0195: openssl - The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1... The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment. Scope: local
debian
CVE-2016-0800P2MEDIUMCVSS 5.9PoCfixed in nss 3.13 (bookworm)2016
CVE-2016-0800 [MEDIUM] CVE-2016-0800: nss - The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and... The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client possesses certain plaintext RSA data, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a Bleichenbacher RSA padding oracle, aka a "DROWN" attack. Scope:
debian
CVE-2016-2107P2LOWCVSS 2.6PoCfixed in openssl 1.0.2h-1 (bookworm)2016
CVE-2016-2107 [LOW] CVE-2016-2107: openssl - The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does ... The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-0169. Scope: local bookworm
debian
CVE-2015-1793P2MEDIUMCVSS 6.5PoCfixed in openssl 1.0.2d-1 (bookworm)2015
CVE-2015-1793 [MEDIUM] CVE-2015-1793: openssl - The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1... The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
debian
CVE-2008-0166P2HIGHCVSS 7.5PoCfixed in openssh 4.7p1-9 (bookworm)2008
CVE-2008-0166 [HIGH] CVE-2008-0166: openssh - OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating system... OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys. Scope: local bookworm: resolved (fixed in 4.7p1-9) bullseye: resolved (fixed in 4.7p1-9) forky: resolved (fixe
debian
CVE-2017-3730P2HIGHCVSS 7.5PoCfixed in openssl 1.1.0d-1 (bookworm)2017
CVE-2017-3730 [HIGH] CVE-2017-3730: openssl - In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters fo... In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack. Scope: local bookworm: resolved (fixed in 1.1.0d-1) bullseye: resolved (fixed in 1.1.0d-1) forky: reso
debian
CVE-2012-2110P2HIGHCVSS 7.5PoCfixed in openssl 1.0.1a-1 (bookworm)2012
CVE-2012-2110 [HIGH] CVE-2012-2110: openssl - The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8... The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in OpenSSL before 0.9.8v, 1.0.0 before 1.0.0i, and 1.0.1 before 1.0.1a does not properly interpret integer data, which allows remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by
debian
CVE-2024-4741P3HIGHCVSS 7.5Exploitedfixed in openssl 3.0.14-1~deb12u1 (bookworm)2024
CVE-2024-4741 [HIGH] CVE-2024-4741: openssl - Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memor... Issue summary: Calling the OpenSSL API function SSL_free_buffers may cause memory to be accessed that was previously freed in some situations Impact summary: A use after free can have a range of potential consequences such as the corruption of valid data, crashes or execution of arbitrary code. However, only applications that directly call the SSL_free_buffers functio
debian
CVE-2021-3711P2CRITICALCVSS 9.8fixed in openssl 1.1.1l-1 (bookworm)2021
CVE-2021-3711 [CRITICAL] CVE-2021-3711: openssl - In order to decrypt SM2 encrypted data an application is expected to call the AP... In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be NULL and, on exit, the "outlen" parameter is populated with the buffer size required to hold the decrypted plaintext. The application can then all
debian
CVE-2015-4000P3LOWCVSS 3.7PoCfixed in nss 2:3.19.1-1 (bookworm)2015
CVE-2015-4000 [LOW] CVE-2015-4000: nss - The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a ... The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" is
debian
CVE-2002-0656P3HIGHCVSS 7.5PoCfixed in openssl 0.9.6e-1 (bookworm)2002
CVE-2002-0656 [HIGH] CVE-2002-0656: openssl - Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, all... Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3. Scope: local bookworm: resolved (fixed in 0.9.6e-1) bullseye: resolved (fixed in 0.9.6e-1) forky: resolved (fixed in 0.9.6e-1) sid: resolved (fixed in 0.9.6e-1) trixie
debian
CVE-2025-15467P2HIGHCVSS 8.8fixed in openssl 3.0.18-1~deb12u2 (bookworm)2025
CVE-2025-15467 [HIGH] CVE-2025-15467: openssl - Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with malic... Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When parsing CMS (Auth)EnvelopedData structures that use AEAD ciphers such as AES-GCM, the IV
debian
CVE-2016-7054P3HIGHCVSS 7.5PoCfixed in openssl 1.1.0c-1 (bookworm)2016
CVE-2016-7054 [HIGH] CVE-2016-7054: openssl - In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 cipher... In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS. Scope: local bookworm: resolved (fixed in 1.1.0c-1) bullseye: resolved (fixed in 1.1.0c-1) forky: resolved (fixed in 1.1.0
debian
CVE-2022-3602P2HIGHCVSS 7.5fixed in openssl 3.0.7-1 (bookworm)2022
CVE-2022-3602 [HIGH] CVE-2022-3602: openssl - A buffer overrun can be triggered in X.509 certificate verification, specificall... A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer. An atta
debian
CVE-2016-2108P2CRITICALCVSS 9.8fixed in openssl 1.0.2c-1 (bookworm)2016
CVE-2016-2108 [CRITICAL] CVE-2016-2108: openssl - The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows... The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue. Scope: local bookworm: resolved (fixed in 1.0.2c-1) bullseye: resolved (fixed in 1.0.2c-1) forky
debian
CVE-2022-3786P2HIGHCVSS 7.5fixed in openssl 3.0.7-1 (bookworm)2022
CVE-2022-3786 [HIGH] CVE-2022-3786: openssl - A buffer overrun can be triggered in X.509 certificate verification, specificall... A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacke
debian
CVE-2014-3566P3LOWCVSS 3.4PoCfixed in erlang 1:17.3-dfsg-3 (bookworm)2014
CVE-2014-3566 [LOW] CVE-2014-3566: bouncycastle - The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses... The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
1 / 13Next →
Debian OpenSSL vulnerabilities | cvebase