Debian OpenSSL vulnerabilities
249 known vulnerabilities affecting debian/openssl.
Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2
Vulnerabilities
Page 5 of 13
CVE-2018-5407P4MEDIUMCVSS 4.7PoCfixed in openssl 1.1.1~~pre9-1 (bookworm)2018
CVE-2018-5407 [MEDIUM] CVE-2018-5407: openssl - Simultaneous Multi-threading (SMT) in processors can enable local users to explo...
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
Scope: local
bookworm: resolved (fixed in 1.1.1~~pre9-1)
bullseye: resolved (fixed in 1.1.1~~pre9-1)
forky: resolved (fixed in 1.1.1~~pre9-1)
sid: resolved (fixed in 1.1.1~~pre9-1)
trixie: res
debian
CVE-2026-31790P3HIGHCVSS 7.5fixed in openssl 3.0.19-1~deb12u2 (bookworm)2026
CVE-2026-31790 [HIGH] CVE-2026-31790: openssl - Issue summary: Applications using RSASVE key encapsulation to establish a secret...
Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitialized buffer might contain sensitive data from the previous execution of the application process which leads to sensitive data leakage to an attacker. RSA_public_encrypt()
debian
CVE-2003-0078P4MEDIUMCVSS 5.0PoCfixed in openssl 0.9.7a-1 (bookworm)2003
CVE-2003-0078 [MEDIUM] CVE-2003-0078: openssl - ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i do...
ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extrac
debian
CVE-2003-0543P4MEDIUMCVSS 5.0PoCfixed in openssl 0.9.7c (bookworm)2003
CVE-2003-0543 [MEDIUM] CVE-2003-0543: openssl - Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a d...
Integer overflow in OpenSSL 0.9.6 and 0.9.7 allows remote attackers to cause a denial of service (crash) via an SSL client certificate with certain ASN.1 tag values.
Scope: local
bookworm: resolved (fixed in 0.9.7c)
bullseye: resolved (fixed in 0.9.7c)
forky: resolved (fixed in 0.9.7c)
sid: resolved (fixed in 0.9.7c)
trixie: resolved (fixed in 0.9.7c)
debian
CVE-2007-4995P3LOWCVSS 9.3fixed in openssl 0.9.8f-1 (bookworm)2007
CVE-2007-4995 [CRITICAL] CVE-2007-4995: openssl - Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allow...
Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 0.9.8f-1)
bullseye: resolved (fixed in 0.9.8f-1)
forky: resolved (fixed in 0.9.8f-1)
sid: resolved (fixed in 0.9.8f-1)
trixie: resolved (fixed in 0.9.8f-1)
debian
CVE-2006-4343P4MEDIUMCVSS 4.3PoCfixed in openssl 0.9.8c-2 (bookworm)2006
CVE-2006-4343 [MEDIUM] CVE-2006-4343: openssl - The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0...
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.
Scope: local
bookworm: resolved (fixed in 0.9.8c-2)
bullseye: resolved (fixed in 0.9.8c-2)
forky: resolved (fixe
debian
CVE-2010-0742P3LOWCVSS 7.5fixed in openssl 1.0.0e-1 (bookworm)2010
CVE-2010-0742 [HIGH] CVE-2010-0742: openssl - The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c i...
The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL before 0.9.8o and 1.x before 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent attackers to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.
Scope: lo
debian
CVE-2025-9230P3HIGHCVSS 7.5fixed in openssl 3.0.17-1~deb12u3 (bookworm)2025
CVE-2025-9230 [HIGH] CVE-2025-9230: openssl - Issue summary: An application trying to decrypt CMS messages encrypted using pas...
Issue summary: An application trying to decrypt CMS messages encrypted using password based encryption can trigger an out-of-bounds read and write. Impact summary: This out-of-bounds read may trigger a crash which leads to Denial of Service for an application. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial
debian
CVE-2025-69419P3HIGHCVSS 7.4fixed in openssl 3.0.18-1~deb12u2 (bookworm)2025
CVE-2025-69419 [HIGH] CVE-2025-69419: openssl - Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously craft...
Issue summary: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. Impact summary: The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.
debian
CVE-2023-5363P3HIGHCVSS 7.5fixed in openssl 3.0.11-1~deb12u2 (bookworm)2023
CVE-2023-5363 [HIGH] CVE-2023-5363: openssl - Issue summary: A bug has been identified in the processing of key and initialisa...
Issue summary: A bug has been identified in the processing of key and initialisation vector (IV) lengths. This can lead to potential truncation or overruns during the initialisation of some symmetric ciphers. Impact summary: A truncation in the IV can result in non-uniqueness, which could result in loss of confidentiality for some cipher modes. When calling EVP_Encryp
debian
CVE-2015-3195P3MEDIUMCVSS 5.3fixed in openssl 1.0.2e-1 (bookworm)2015
CVE-2015-3195 [MEDIUM] CVE-2015-3195: openssl - The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before...
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS application.
Scope:
debian
CVE-2012-2333P3MEDIUMCVSS 6.8fixed in openssl 1.0.1c-1 (bookworm)2012
CVE-2012-2333 [MEDIUM] CVE-2012-2333: openssl - Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 befor...
Integer underflow in OpenSSL before 0.9.8x, 1.0.0 before 1.0.0j, and 1.0.1 before 1.0.1c, when TLS 1.1, TLS 1.2, or DTLS is used with CBC encryption, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted TLS packet that is not properly handled during a certain explicit IV calculation.
Scope: l
debian
CVE-2016-0701P4LOWCVSS 3.7fixed in openssl 1.0.2f-2 (bookworm)2016
CVE-2016-0701 [LOW] CVE-2016-0701: openssl - The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1....
The DH_check_pub_key function in crypto/dh/dh_check.c in OpenSSL 1.0.2 before 1.0.2f does not ensure that prime numbers are appropriate for Diffie-Hellman (DH) key exchange, which makes it easier for remote attackers to discover a private DH exponent by making multiple handshakes with a peer that chose an inappropriate number, as demonstrated by a number in an X9.42 fi
debian
CVE-2015-0205P3MEDIUMCVSS 5.0fixed in openssl 1.0.1k-1 (bookworm)2015
CVE-2015-0205 [MEDIUM] CVE-2015-0205: openssl - The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p an...
The ssl3_get_cert_verify function in s3_srvr.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k accepts client authentication with a Diffie-Hellman (DH) certificate without requiring a CertificateVerify message, which allows remote attackers to obtain access without knowledge of a private key via crafted TLS Handshake Protocol traffic to a server that recogniz
debian
CVE-2023-0464P3HIGHCVSS 7.5fixed in openssl 3.0.9-1 (bookworm)2023
CVE-2023-0464 [HIGH] CVE-2023-0464: openssl - A security vulnerability has been identified in all supported versions of OpenS...
A security vulnerability has been identified in all supported versions of OpenSSL related to the verification of X.509 certificate chains that include policy constraints. Attackers may be able to exploit this vulnerability by creating a malicious certificate chain that triggers exponential use of computational resources, leading to a denial-of-service (DoS) attack on
debian
CVE-2015-0206P3MEDIUMCVSS 5.0fixed in openssl 1.0.1k-1 (bookworm)2015
CVE-2015-0206 [MEDIUM] CVE-2015-0206: openssl - Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 bef...
Memory leak in the dtls1_buffer_record function in d1_pkt.c in OpenSSL 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k allows remote attackers to cause a denial of service (memory consumption) by sending many duplicate records for the next epoch, leading to failure of replay detection.
Scope: local
bookworm: resolved (fixed in 1.0.1k-1)
bullseye: resolved (fixed in 1.0.
debian
CVE-2023-0215P3HIGHCVSS 7.5fixed in openssl 3.0.8-1 (bookworm)2023
CVE-2023-0215 [HIGH] CVE-2023-0215: openssl - The public API function BIO_new_NDEF is a helper function used for streaming ASN...
The public API function BIO_new_NDEF is a helper function used for streaming ASN.1 data via a BIO. It is primarily used internally to OpenSSL to support the SMIME, CMS and PKCS7 streaming capabilities, but may also be called directly by end user applications. The function receives a BIO from the caller, prepends a new BIO_f_asn1 filter BIO onto the front of it to form
debian
CVE-2016-6306P3MEDIUMCVSS 5.9fixed in openssl 1.0.2i-1 (bookworm)2016
CVE-2016-6306 [MEDIUM] CVE-2016-6306: openssl - The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might al...
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
Scope: local
bookworm: resolved (fixed in 1.0.2i-1)
bullseye: resolved (fixed in 1.0.2i-1)
forky: resolved (fixed in 1.0.2i-1)
sid: resolved (fix
debian
CVE-2026-28390P3HIGHCVSS 7.5fixed in openssl 3.0.19-1~deb12u2 (bookworm)2026
CVE-2026-28390 [HIGH] CVE-2026-28390: openssl - Issue summary: During processing of a crafted CMS EnvelopedData message with Key...
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRe
debian
CVE-2026-28389P3HIGHCVSS 7.5fixed in openssl 3.0.19-1~deb12u2 (bookworm)2026
CVE-2026-28389 [HIGH] CVE-2026-28389: openssl - Issue summary: During processing of a crafted CMS EnvelopedData message with Key...
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyAgreeRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyAgreeRecipientI
debian