Debian OpenSSL vulnerabilities
249 known vulnerabilities affecting debian/openssl.
Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2
Vulnerabilities
Page 12 of 13
CVE-2011-4577P4LOWCVSS 4.3fixed in openssl 1.0.0f-1 (bookworm)2011
CVE-2011-4577 [MEDIUM] CVE-2011-4577: openssl - OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, a...
OpenSSL before 0.9.8s and 1.x before 1.0.0f, when RFC 3779 support is enabled, allows remote attackers to cause a denial of service (assertion failure) via an X.509 certificate containing certificate-extension data associated with (1) IP address blocks or (2) Autonomous System (AS) identifiers.
Scope: local
bookworm: resolved (fixed in 1.0.0f-1)
bullseye: resolved (
debian
CVE-2022-4203P4MEDIUMCVSS 4.9fixed in openssl 3.0.8-1 (bookworm)2022
CVE-2022-4203 [MEDIUM] CVE-2022-4203: openssl - A read buffer overrun can be triggered in X.509 certificate verification, specif...
A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite failure to construct a path to a trusted issuer.
debian
CVE-2019-1547P4MEDIUMCVSS 4.7fixed in openssl 1.1.1d-1 (bookworm)2019
CVE-2019-1547 [MEDIUM] CVE-2019-1547: openssl - Normally in OpenSSL EC groups always have a co-factor present and this is used i...
Normally in OpenSSL EC groups always have a co-factor present and this is used in side channel resistant code paths. However, in some cases, it is possible to construct a group using explicit parameters (instead of using a named curve). In those cases it is possible that such a group does not have the cofactor present. This can occur even where all the parameters ma
debian
CVE-2003-0147P4MEDIUMCVSS 5.0fixed in openssl 0.9.7b-1 (bookworm)2003
CVE-2003-0147 [MEDIUM] CVE-2003-0147: openssl - OpenSSL does not use RSA blinding by default, which allows local and remote atta...
OpenSSL does not use RSA blinding by default, which allows local and remote attackers to obtain the server's private key by determining factors using timing differences on (1) the number of extra reductions during Montgomery reduction, and (2) the use of different integer multiplication algorithms ("Karatsuba" and normal).
Scope: local
bookworm: resolved (fixed in 0
debian
CVE-2009-0590P4LOWCVSS 5.0fixed in openssl 0.9.8g-16 (bookworm)2009
CVE-2009-0590 [MEDIUM] CVE-2009-0590: openssl - The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attacke...
The ASN1_STRING_print_ex function in OpenSSL before 0.9.8k allows remote attackers to cause a denial of service (invalid memory access and application crash) via vectors that trigger printing of a (1) BMPString or (2) UniversalString with an invalid encoded length.
Scope: local
bookworm: resolved (fixed in 0.9.8g-16)
bullseye: resolved (fixed in 0.9.8g-16)
forky: re
debian
CVE-2011-3210P4MEDIUMCVSS 5.0fixed in openssl 1.0.0e-1 (bookworm)2011
CVE-2011-3210 [MEDIUM] CVE-2011-3210: openssl - The ephemeral ECDH ciphersuite functionality in OpenSSL 0.9.8 through 0.9.8r and...
The ephemeral ECDH ciphersuite functionality in OpenSSL 0.9.8 through 0.9.8r and 1.0.x before 1.0.0e does not ensure thread safety during processing of handshake messages from clients, which allows remote attackers to cause a denial of service (daemon crash) via out-of-order messages that violate the TLS protocol.
Scope: local
bookworm: resolved (fixed in 1.0.0e-1)
debian
CVE-2024-0727P4MEDIUMCVSS 5.5fixed in openssl 3.0.13-1~deb12u1 (bookworm)2024
CVE-2024-0727 [MEDIUM] CVE-2024-0727: openssl - Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL t...
Issue summary: Processing a maliciously formatted PKCS12 file may lead OpenSSL to crash leading to a potential Denial of Service attack Impact summary: Applications loading files in the PKCS12 format from untrusted sources might terminate abruptly. A file in PKCS12 format can contain certificates and keys and may come from an untrusted source. The PKCS12 specificati
debian
CVE-2004-0081P4MEDIUMCVSS 5.0fixed in openssl 0.9.6d-1 (bookworm)2004
CVE-2004-0081 [MEDIUM] CVE-2004-0081: openssl - OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, whic...
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
Scope: local
bookworm: resolved (fixed in 0.9.6d-1)
bullseye: resolved (fixed in 0.9.6d-1)
forky: resolved (fixed in 0.9.6d-1)
sid: resolved (fixed in 0.9.6d-1)
tr
debian
CVE-2008-7270P4MEDIUMCVSS 4.3fixed in openssl 0.9.8k-1 (bookworm)2008
CVE-2008-7270 [MEDIUM] CVE-2008-7270: openssl - OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, ...
OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180.
Scope: local
bookworm:
debian
CVE-2012-1165P4LOWCVSS 5.0fixed in openssl 1.0.0h-1 (bookworm)2012
CVE-2012-1165 [MEDIUM] CVE-2012-1165: openssl - The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u a...
The mime_param_cmp function in crypto/asn1/asn_mime.c in OpenSSL before 0.9.8u and 1.x before 1.0.0h allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted S/MIME message, a different vulnerability than CVE-2006-7250.
Scope: local
bookworm: resolved (fixed in 1.0.0h-1)
bullseye: resolved (fixed in 1.0.0h-1
debian
CVE-2003-0544P4MEDIUMCVSS 5.0fixed in openssl 0.9.7c (bookworm)2003
CVE-2003-0544 [MEDIUM] CVE-2003-0544: openssl - OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in cert...
OpenSSL 0.9.6 and 0.9.7 does not properly track the number of characters in certain ASN.1 inputs, which allows remote attackers to cause a denial of service (crash) via an SSL client certificate that causes OpenSSL to read past the end of a buffer when the long form is used.
Scope: local
bookworm: resolved (fixed in 0.9.7c)
bullseye: resolved (fixed in 0.9.7c)
forky
debian
CVE-2013-4353P4MEDIUMCVSS 4.3fixed in openssl 1.0.1f-1 (bookworm)2013
CVE-2013-4353 [MEDIUM] CVE-2013-4353: openssl - The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allow...
The ssl3_take_mac function in ssl/s3_both.c in OpenSSL 1.0.1 before 1.0.1f allows remote TLS servers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Next Protocol Negotiation record in a TLS handshake.
Scope: local
bookworm: resolved (fixed in 1.0.1f-1)
bullseye: resolved (fixed in 1.0.1f-1)
forky: resolved (fixed in 1.0.1
debian
CVE-2008-1672P4MEDIUMCVSS 4.3fixed in openssl 0.9.8g-10.1 (bookworm)2008
CVE-2008-1672 [MEDIUM] CVE-2008-1672: openssl - OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (...
OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.9.8g-10.1)
bullseye: resolved (fixed in 0.9.8g-10.1)
forky: resolved (fixed in 0.9.8g-10.1)
si
debian
CVE-2020-1968P4LOWCVSS 3.7fixed in openssl 1.1.0c-1 (bookworm)2020
CVE-2020-1968 [LOW] CVE-2020-1968: openssl - The Raccoon attack exploits a flaw in the TLS specification which can lead to an...
The Raccoon attack exploits a flaw in the TLS specification which can lead to an attacker being able to compute the pre-master secret in connections which have used a Diffie-Hellman (DH) based ciphersuite. In such a case this would result in the attacker being able to eavesdrop on all encrypted communications sent over that TLS connection. The attack can only be exploi
debian
CVE-2026-22795P4MEDIUMCVSS 5.5fixed in openssl 3.0.18-1~deb12u2 (bookworm)2026
CVE-2026-22795 [MEDIUM] CVE-2026-22795: openssl - Issue summary: An invalid or NULL pointer dereference can happen in an applicati...
Issue summary: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. Impact summary: An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service. A type confusion vulnerability exists in PKCS#12 parsing code where an AS
debian
CVE-2005-2946P4LOWCVSS 7.5fixed in openssl 0.9.8-1 (bookworm)2005
CVE-2005-2946 [HIGH] CVE-2005-2946: openssl - The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message ...
The default configuration on OpenSSL before 0.9.8 uses MD5 for creating message digests instead of a more cryptographically strong algorithm, which makes it easier for remote attackers to forge certificates with a valid certificate authority signature.
Scope: local
bookworm: resolved (fixed in 0.9.8-1)
bullseye: resolved (fixed in 0.9.8-1)
forky: resolved (fixed in 0.
debian
CVE-2019-1563P4LOWCVSS 3.7fixed in openssl 1.1.1d-1 (bookworm)2019
CVE-2019-1563 [LOW] CVE-2019-1563: openssl - In situations where an attacker receives automated notification of the success o...
In situations where an attacker receives automated notification of the success or failure of a decryption attempt an attacker, after sending a very large number of messages to be decrypted, can recover a CMS/PKCS7 transported encryption key or decrypt any RSA encrypted message that was encrypted with the public RSA key, using a Bleichenbacher padding oracle attack. App
debian
CVE-2025-68160P4MEDIUMCVSS 4.7fixed in openssl 3.0.18-1~deb12u2 (bookworm)2025
CVE-2025-68160 [MEDIUM] CVE-2025-68160: openssl - Issue summary: Writing large, newline-free data into a BIO chain using the line-...
Issue summary: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. Impact summary: This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application. The line-buffering BIO filte
debian
CVE-2008-0891P4MEDIUMCVSS 4.3fixed in openssl 0.9.8g-10.1 (bookworm)2008
CVE-2008-0891 [MEDIUM] CVE-2008-0891: openssl - Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name...
Double free vulnerability in OpenSSL 0.9.8f and 0.9.8g, when the TLS server name extensions are enabled, allows remote attackers to cause a denial of service (crash) via a malformed Client Hello packet. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 0.9.8g-10.1)
bullseye: resolved (fixed in 0.9.8g-10.
debian
CVE-2021-23839P4LOWCVSS 3.7fixed in openssl 1.0.0d-1 (bookworm)2021
CVE-2021-23839 [LOW] CVE-2021-23839: openssl - OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a ser...
OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed to use a special form of padding. A server that su
debian