cbcvebase.

Debian OpenSSL vulnerabilities

249 known vulnerabilities affecting debian/openssl.

Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2

Vulnerabilities

Page 13 of 13
CVE-2025-69418P4MEDIUMCVSS 4.0fixed in openssl 3.0.18-1~deb12u2 (bookworm)2025
CVE-2025-69418 [MEDIUM] CVE-2025-69418: openssl - Issue summary: When using the low-level OCB API directly with AES-NI or<br>other... Issue summary: When using the low-level OCB API directly with AES-NI orother hardware-accelerated code paths, inputs whose length is not a multipleof 16 bytes can leave the final partial block unencrypted and unauthenticated.Impact summary: The trailing 1-15 bytes of a message may be exposed incleartext on encryption and are not covered by the authentication tag,a
debian
CVE-2024-13176P4MEDIUMCVSS 4.1fixed in edk2 2025.02-9 (forky)2024
CVE-2024-13176 [MEDIUM] CVE-2024-13176: edk2 - Issue summary: A timing side-channel which could potentially allow recovering th... Issue summary: A timing side-channel which could potentially allow recovering the private key exists in the ECDSA signature computation. Impact summary: A timing side-channel in ECDSA signature computations could allow recovering the private key by an attacker. However, measuring the timing would require either local access to the signing application or a very fast n
debian
CVE-2011-5095P4MEDIUMCVSS 4.0fixed in openssl 0.9.8a-1 (bookworm)2011
CVE-2011-5095 [MEDIUM] CVE-2011-5095: openssl - The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode ... The Diffie-Hellman key-exchange implementation in OpenSSL 0.9.8, when FIPS mode is enabled, does not properly validate a public parameter, which makes it easier for man-in-the-middle attackers to obtain the shared secret key by modifying network traffic, a related issue to CVE-2011-1923. Scope: local bookworm: resolved (fixed in 0.9.8a-1) bullseye: resolved (fixed i
debian
CVE-2002-1568P4MEDIUMCVSS 5.0fixed in openssl 0.9.6g-1 (bookworm)2002
CVE-2002-1568 [MEDIUM] CVE-2002-1568: openssl - OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of... OpenSSL 0.9.6e uses assertions when detecting buffer overflow attacks instead of less severe mechanisms, which allows remote attackers to cause a denial of service (crash) via certain messages that cause OpenSSL to abort from a failed assertion, as demonstrated using SSLv2 CLIENT_MASTER_KEY messages, which are not properly handled in s2_srvr.c. Scope: local bookworm
debian
CVE-2012-4929P4LOWCVSS 2.6fixed in apache2 2.2.22-12 (bookworm)2012
CVE-2012-4929 [LOW] CVE-2012-4929: apache2 - The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt,... The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potenti
debian
CVE-2011-1945P4LOWCVSS 2.6fixed in openssl 1.0.0e-1 (bookworm)2011
CVE-2011-1945 [LOW] CVE-2011-1945: openssl - The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, w... The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation. Scope: l
debian
CVE-2014-0076P4LOWCVSS 1.9fixed in openssl 1.0.1g-1 (bookworm)2014
CVE-2014-0076 [LOW] CVE-2014-0076: openssl - The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure t... The Montgomery ladder implementation in OpenSSL through 1.0.0l does not ensure that certain swap operations have a constant-time behavior, which makes it easier for local users to obtain ECDSA nonces via a FLUSH+RELOAD cache side-channel attack. Scope: local bookworm: resolved (fixed in 1.0.1g-1) bullseye: resolved (fixed in 1.0.1g-1) forky: resolved (fixed in 1.0.1g-1
debian
CVE-2007-3108P4LOWCVSS 1.2fixed in openssl 0.9.8e-6 (bookworm)2007
CVE-2007-3108 [LOW] CVE-2007-3108: openssl - The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and ear... The BN_from_montgomery function in crypto/bn/bn_mont.c in OpenSSL 0.9.8e and earlier does not properly perform Montgomery multiplication, which might allow local users to conduct a side-channel attack and retrieve RSA private keys. Scope: local bookworm: resolved (fixed in 0.9.8e-6) bullseye: resolved (fixed in 0.9.8e-6) forky: resolved (fixed in 0.9.8e-6) sid: resolve
debian
CVE-2004-0975P4LOWCVSS 2.1fixed in openssl 0.9.7e-3 (bookworm)2004
CVE-2004-0975 [LOW] CVE-2004-0975: openssl - The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2... The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files. Scope: local bookworm: resolved (fixed in 0.9.7e-3) bullseye: resolved (fixed in 0.9.7e-3) forky: resolved (fixed in 0.9.7e-3) sid: resolved (fixed in 0.9.7e-3) trixie: resolved (fi
debian
Debian OpenSSL vulnerabilities | cvebase