cbcvebase.

Debian OpenSSL vulnerabilities

249 known vulnerabilities affecting debian/openssl.

Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2

Vulnerabilities

Page 7 of 13
CVE-2014-3507P4MEDIUMCVSS 5.0fixed in openssl 1.0.1i-1 (bookworm)2014
CVE-2014-3507 [MEDIUM] CVE-2014-3507: openssl - Memory leak in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.... Memory leak in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (memory consumption) via zero-length DTLS fragments that trigger improper handling of the return value of a certain insert function. Scope: local bookworm: resolved (fixed in 1.0.1i-1)
debian
CVE-2018-0737P3LOWCVSS 5.9fixed in openssl 1.1.0h-3 (bookworm)2018
CVE-2018-0737 [MEDIUM] CVE-2018-0737: openssl - The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a ca... The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2b-1.0.2o). Scope: local bo
debian
CVE-2025-69421P3HIGHCVSS 7.5fixed in openssl 3.0.18-1~deb12u2 (bookworm)2025
CVE-2025-69421 [HIGH] CVE-2025-69421: openssl - Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer de... Issue summary: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. Impact summary: A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files. The PKCS12_item_decrypt_d2i_ex() function does not check whether the oct parameter is NULL
debian
CVE-2025-9231P3LOWCVSS 6.5fixed in openssl 3.5.4-1 (forky)2025
CVE-2025-9231 [MEDIUM] CVE-2025-9231: openssl - Issue summary: A timing side-channel which could potentially allow remote recove... Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64 bit ARM platforms. Impact summary: A timing side-channel in SM2 signature computations on 64 bit ARM platforms could allow recovering the private key by an attacker.. While remote key recovery over a network was not a
debian
CVE-2018-0733P3LOWCVSS 5.9fixed in openssl 1.1.0h-1 (bookworm)2018
CVE-2018-0733 [MEDIUM] CVE-2018-0733: openssl - Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effective... Because of an implementation bug the PA-RISC CRYPTO_memcmp function is effectively reduced to only comparing the least significant bit of each byte. This allows an attacker to forge messages that would be considered as authenticated in an amount of tries lower than that guaranteed by the security claims of the scheme. The module can only be compiled by the HP-UX ass
debian
CVE-2000-1254P3HIGHCVSS 7.5fixed in openssl 0.9.6-1 (bookworm)2000
CVE-2000-1254 [HIGH] CVE-2000-1254: openssl - crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operatio... crypto/rsa/rsa_gen.c in OpenSSL before 0.9.6 mishandles C bitwise-shift operations that exceed the size of an expression, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging improper RSA key generation on 64-bit HP-UX platforms. Scope: local bookworm: resolved (fixed in 0.9.6-1) bullseye: resolved (fixed in 0.9.6-1) f
debian
CVE-2018-0734P3MEDIUMCVSS 5.9fixed in openssl 1.1.1a-1 (bookworm)2018
CVE-2018-0734 [MEDIUM] CVE-2018-0734: openssl - The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing ... The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected 1.0.2-1.0.2p). Scope: local bookworm: resolved (fixed in
debian
CVE-2015-0209P3MEDIUMCVSS 6.8fixed in openssl 1.0.1k-2 (bookworm)2015
CVE-2015-0209 [MEDIUM] CVE-2015-0209: openssl - Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_as... Use-after-free vulnerability in the d2i_ECPrivateKey function in crypto/ec/ec_asn1.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a malformed Elliptic Curve (EC) private-key
debian
CVE-2015-1791P3MEDIUMCVSS 6.8fixed in openssl 1.0.2b-1 (bookworm)2015
CVE-2015-1791 [MEDIUM] CVE-2015-1791: openssl - Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in O... Race condition in the ssl3_get_new_session_ticket function in ssl/s3_clnt.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b, when used for a multi-threaded client, allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact by providing a NewSessionTic
debian
CVE-2022-3996P3HIGHCVSS 7.5fixed in openssl 3.0.7-2 (bookworm)2022
CVE-2022-3996 [HIGH] CVE-2022-3996: openssl - If an X.509 certificate contains a malformed policy constraint and policy proces... If an X.509 certificate contains a malformed policy constraint and policy processing is enabled, then a write lock will be taken twice recursively. On some operating systems (most widely: Windows) this results in a denial of service when the affected process hangs. Policy processing being enabled on a publicly facing server is not considered to be a common setup. Poli
debian
CVE-2014-3505P4MEDIUMCVSS 5.0fixed in openssl 1.0.1i-1 (bookworm)2014
CVE-2014-3505 [MEDIUM] CVE-2014-3505: openssl - Double free vulnerability in d1_both.c in the DTLS implementation in OpenSSL 0.9... Double free vulnerability in d1_both.c in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i allows remote attackers to cause a denial of service (application crash) via crafted DTLS packets that trigger an error condition. Scope: local bookworm: resolved (fixed in 1.0.1i-1) bullseye: resolved (fixed in 1.0.1i-1) fo
debian
CVE-2026-2673P3LOWCVSS 7.5fixed in openssl 3.5.5-1~deb13u2 (trixie)2026
CVE-2026-2673 [HIGH] CVE-2026-2673: openssl - Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected pref... Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client and server, if the group was not included among the
debian
CVE-2017-3735P3MEDIUMCVSS 5.3fixed in openssl 1.1.0g-1 (bookworm)2017
CVE-2017-3735 [MEDIUM] CVE-2017-3735: openssl - While parsing an IPAddressFamily extension in an X.509 certificate, it is possib... While parsing an IPAddressFamily extension in an X.509 certificate, it is possible to do a one-byte overread. This would result in an incorrect text display of the certificate. This bug has been present since 2006 and is present in all versions of OpenSSL before 1.0.2m and 1.1.0g. Scope: local bookworm: resolved (fixed in 1.1.0g-1) bullseye: resolved (fixed in 1.1.0
debian
CVE-2014-0198P4MEDIUMCVSS 4.3fixed in openssl 1.0.1g-4 (bookworm)2014
CVE-2014-0198 [MEDIUM] CVE-2014-0198: openssl - The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_M... The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition. Scope: local bookworm: resolv
debian
CVE-2014-3509P3MEDIUMCVSS 6.8fixed in openssl 1.0.1i-1 (bookworm)2014
CVE-2014-3509 [MEDIUM] CVE-2014-3509: openssl - Race condition in the ssl_parse_serverhello_tlsext function in t1_lib.c in OpenS... Race condition in the ssl_parse_serverhello_tlsext function in t1_lib.c in OpenSSL 1.0.0 before 1.0.0n and 1.0.1 before 1.0.1i, when multithreading and session resumption are used, allows remote SSL servers to cause a denial of service (memory overwrite and client application crash) or possibly have unspecified other impact by sending Elliptic Curve (EC) Supported P
debian
CVE-2021-23841P3MEDIUMCVSS 5.9fixed in openssl 1.1.1j-1 (bookworm)2021
CVE-2021-23841 [MEDIUM] CVE-2021-23841: openssl - The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create... The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate. However it fails to correctly handle any errors that may occur while parsing the issuer field (which might occur if the issuer field is maliciously constructed). This may subsequently
debian
CVE-2016-0704P3MEDIUMCVSS 5.9fixed in openssl 1.0.0c-2 (bookworm)2016
CVE-2016-0704 [MEDIUM] CVE-2016-0704: openssl - An oracle protection mechanism in the get_client_master_key function in s2_srvr.... An oracle protection mechanism in the get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a overwrites incorrect MASTER-KEY bytes during use of export cipher suites, which makes it easier for remote attackers to decrypt TLS ciphertext data by leveraging a B
debian
CVE-2019-1551P3LOWCVSS 5.3fixed in openssl 1.1.1e-1 (bookworm)2019
CVE-2019-1551 [MEDIUM] CVE-2019-1551: openssl - There is an overflow bug in the x64_64 Montgomery squaring procedure used in exp... There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are considered just feasib
debian
CVE-2023-0217P3HIGHCVSS 7.5fixed in openssl 3.0.8-1 (bookworm)2023
CVE-2023-0217 [HIGH] CVE-2023-0217: openssl - An invalid pointer dereference on read can be triggered when an application trie... An invalid pointer dereference on read can be triggered when an application tries to check a malformed DSA public key by the EVP_PKEY_public_check() function. This will most likely lead to an application crash. This function can be called on public keys supplied from untrusted sources which could allow an attacker to cause a denial of service attack. The TLS implement
debian
CVE-2016-0703P3MEDIUMCVSS 5.9fixed in openssl 1.0.0c-2 (bookworm)2016
CVE-2016-0703 [MEDIUM] CVE-2016-0703: openssl - The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in O... The get_client_master_key function in s2_srvr.c in the SSLv2 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a accepts a nonzero CLIENT-MASTER-KEY CLEAR-KEY-LENGTH value for an arbitrary cipher, which allows man-in-the-middle attackers to determine the MASTER-KEY value and decrypt TLS ciphertext data by lever
debian
Debian OpenSSL vulnerabilities | cvebase