Debian OpenSSL vulnerabilities
249 known vulnerabilities affecting debian/openssl.
Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2
Vulnerabilities
Page 10 of 13
CVE-2012-0884P4LOWCVSS 5.0fixed in openssl 1.0.0h-1 (bookworm)2012
CVE-2012-0884 [MEDIUM] CVE-2012-0884: openssl - The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL ...
The implementation of Cryptographic Message Syntax (CMS) and PKCS #7 in OpenSSL before 0.9.8u and 1.x before 1.0.0h does not properly restrict certain oracle behavior, which makes it easier for context-dependent attackers to decrypt data via a Million Message Attack (MMA) adaptive chosen ciphertext attack.
Scope: local
bookworm: resolved (fixed in 1.0.0h-1)
bullseye
debian
CVE-2013-0169P4LOWCVSS 2.6fixed in bouncycastle 1.48+dfsg-2 (bookworm)2013
CVE-2013-0169 [LOW] CVE-2013-0169: bouncycastle - The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenS...
The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical anal
debian
CVE-2023-5678P4MEDIUMCVSS 5.3fixed in openssl 3.0.13-1~deb12u1 (bookworm)2023
CVE-2023-5678 [MEDIUM] CVE-2023-5678: openssl - Issue summary: Generating excessively long X9.42 DH keys or checking excessively...
Issue summary: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_generate_key() to generate an X9.42 DH key may experience long delays. Likewise, applications that use DH_check_pub_key(), DH_check_pub_key_ex() or EVP_PKEY_public_check() to check
debian
CVE-2015-7575P4MEDIUMCVSS 5.9fixed in gnutls28 3.3.15-1 (bookworm)2015
CVE-2015-7575 [MEDIUM] CVE-2015-7575: gnutls28 - Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefo...
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
Scope: local
bookworm: resolved (fi
debian
CVE-2023-6237P4MEDIUMCVSS 5.9fixed in openssl 3.0.13-1~deb12u1 (bookworm)2023
CVE-2023-6237 [MEDIUM] CVE-2023-6237: openssl - Issue summary: Checking excessively long invalid RSA public keys may take a long...
Issue summary: Checking excessively long invalid RSA public keys may take a long time. Impact summary: Applications that use the function EVP_PKEY_public_check() to check RSA public keys may experience long delays. Where the key that is being checked has been obtained from an untrusted source this may lead to a Denial of Service. When function EVP_PKEY_public_check(
debian
CVE-2025-27587P4LOWCVSS 5.3fixed in openssl 3.5.0-1 (forky)2025
CVE-2025-27587 [MEDIUM] CVE-2025-27587: openssl - OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Miner...
OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized
debian
CVE-2014-5139P4MEDIUMCVSS 4.3fixed in openssl 1.0.1i-1 (bookworm)2014
CVE-2014-5139 [MEDIUM] CVE-2014-5139: openssl - The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i ...
The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.
Scope: local
bookworm: resolved (fixed in 1.0.1i
debian
CVE-2011-4108P4LOWCVSS 4.3fixed in openssl 1.0.0f-1 (bookworm)2011
CVE-2011-4108 [MEDIUM] CVE-2011-4108: openssl - The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs ...
The DTLS implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f performs a MAC check only if certain padding is valid, which makes it easier for remote attackers to recover plaintext via a padding oracle attack.
Scope: local
bookworm: resolved (fixed in 1.0.0f-1)
bullseye: resolved (fixed in 1.0.0f-1)
forky: resolved (fixed in 1.0.0f-1)
sid: resolved (fixed i
debian
CVE-2009-0653P4HIGHCVSS 7.5fixed in openssl 0.9.8-1 (bookworm)2009
CVE-2009-0653 [HIGH] CVE-2009-0653: openssl - OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermedia...
OpenSSL, probably 0.9.6, does not verify the Basic Constraints for an intermediate CA-signed certificate, which allows remote attackers to spoof the certificates of trusted sites via a man-in-the-middle attack, a related issue to CVE-2002-0970.
Scope: local
bookworm: resolved (fixed in 0.9.8-1)
bullseye: resolved (fixed in 0.9.8-1)
forky: resolved (fixed in 0.9.8-1)
s
debian
CVE-2026-22796P4MEDIUMCVSS 5.3fixed in openssl 3.0.18-1~deb12u2 (bookworm)2026
CVE-2026-22796 [MEDIUM] CVE-2026-22796: openssl - Issue summary: A type confusion vulnerability exists in the signature verificati...
Issue summary: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data. Impact summary: An application performing signature verification of PKCS#7 data or calling direc
debian
CVE-2014-3572P4MEDIUMCVSS 5.0fixed in openssl 1.0.1k-1 (bookworm)2014
CVE-2014-3572 [MEDIUM] CVE-2014-3572: openssl - The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0...
The ssl3_get_key_exchange function in s3_clnt.c in OpenSSL before 0.9.8zd, 1.0.0 before 1.0.0p, and 1.0.1 before 1.0.1k allows remote SSL servers to conduct ECDHE-to-ECDH downgrade attacks and trigger a loss of forward secrecy by omitting the ServerKeyExchange message.
Scope: local
bookworm: resolved (fixed in 1.0.1k-1)
bullseye: resolved (fixed in 1.0.1k-1)
forky:
debian
CVE-2014-3511P4MEDIUMCVSS 4.3fixed in openssl 1.0.1i-1 (bookworm)2014
CVE-2014-3511 [MEDIUM] CVE-2014-3511: openssl - The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i...
The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1 before 1.0.1i allows man-in-the-middle attackers to force the use of TLS 1.0 by triggering ClientHello message fragmentation in communication between a client and server that both support later TLS versions, related to a "protocol downgrade" issue.
Scope: local
bookworm: resolved (fixed in 1.0.1i-1)
debian
CVE-2011-0014P4LOWCVSS 5.0fixed in openssl 0.9.8o-5 (bookworm)2011
CVE-2011-0014 [MEDIUM] CVE-2011-0014: openssl - ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows re...
ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."
Scope: local
bookworm: resolved
debian
CVE-2023-3817P4MEDIUMCVSS 5.3fixed in openssl 3.0.10-1~deb12u1 (bookworm)2023
CVE-2023-3817 [MEDIUM] CVE-2023-3817: openssl - Issue summary: Checking excessively long DH keys or parameters may be very slow....
Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial
debian
CVE-2023-1255P4MEDIUMCVSS 5.9fixed in openssl 3.0.9-1 (bookworm)2023
CVE-2023-1255 [MEDIUM] CVE-2023-1255: openssl - Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platf...
Issue summary: The AES-XTS cipher decryption implementation for 64 bit ARM platform contains a bug that could cause it to read past the input buffer, leading to a crash. Impact summary: Applications that use the AES-XTS algorithm on the 64 bit ARM platform can crash in rare circumstances. The AES-XTS algorithm is usually used for disk encryption. The AES-XTS cipher
debian
CVE-2014-3510P4MEDIUMCVSS 4.3fixed in openssl 1.0.1i-1 (bookworm)2014
CVE-2014-3510 [MEDIUM] CVE-2014-3510: openssl - The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL 0.9.8 before ...
The ssl3_send_client_key_exchange function in s3_clnt.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote DTLS servers to cause a denial of service (NULL pointer dereference and client application crash) via a crafted handshake message in conjunction with a (1) anonymous DH or (2) anonymous ECDH ciphersuite.
Scope: local
boo
debian
CVE-2010-4180P4MEDIUMCVSS 4.3fixed in openssl 0.9.8o-4 (bookworm)2010
CVE-2010-4180 [MEDIUM] CVE-2010-4180: openssl - OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHE...
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
Scope: local
bookworm: re
debian
CVE-2023-2975P4MEDIUMCVSS 5.3fixed in openssl 3.0.10-1~deb12u1 (bookworm)2023
CVE-2023-2975 [MEDIUM] CVE-2023-2975: openssl - Issue summary: The AES-SIV cipher implementation contains a bug that causes it t...
Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be misled by removing, adding or reordering such empty entries as these are ig
debian
CVE-2012-0050P4MEDIUMCVSS 4.3fixed in openssl 1.0.0g-1 (bookworm)2012
CVE-2012-0050 [MEDIUM] CVE-2012-0050: openssl - OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which all...
OpenSSL 0.9.8s and 1.0.0f does not properly support DTLS applications, which allows remote attackers to cause a denial of service (crash) via unspecified vectors related to an out-of-bounds read. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-4108.
Scope: local
bookworm: resolved (fixed in 1.0.0g-1)
bullseye: resolved (fixed in 1.0.0g-1)
fo
debian
CVE-2009-1377P4LOWCVSS 5.0fixed in openssl 0.9.8k-1 (bookworm)2009
CVE-2009-1377 [MEDIUM] CVE-2009-1377: openssl - The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0...
The dtls1_buffer_record function in ssl/d1_pkt.c in OpenSSL 0.9.8k and earlier 0.9.8 versions allows remote attackers to cause a denial of service (memory consumption) via a large series of "future epoch" DTLS records that are buffered in a queue, aka "DTLS record buffer limitation bug."
Scope: local
bookworm: resolved (fixed in 0.9.8k-1)
bullseye: resolved (fixed i
debian