cbcvebase.

Debian OpenSSL vulnerabilities

249 known vulnerabilities affecting debian/openssl.

Total CVEs
249
CISA KEV
1
actively exploited
Public exploits
26
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH70MEDIUM109LOW56UNKNOWN2

Vulnerabilities

Page 9 of 13
CVE-2013-6450P4LOWCVSS 5.8fixed in openssl 1.0.1e-5 (bookworm)2013
CVE-2013-6450 [MEDIUM] CVE-2013-6450: openssl - The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 ... The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-the-middle attackers to trigger the use of a different context and cause a denial of service (application crash) by interfering with packet delivery, related to ssl/d1_bo
debian
CVE-2014-3508P4MEDIUMCVSS 4.3fixed in openssl 1.0.1i-1 (bookworm)2014
CVE-2014-3508 [MEDIUM] CVE-2014-3508: openssl - The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8 before 0.9... The OBJ_obj2txt function in crypto/objects/obj_dat.c in OpenSSL 0.9.8 before 0.9.8zb, 1.0.0 before 1.0.0n, and 1.0.1 before 1.0.1i, when pretty printing is used, does not ensure the presence of '\0' characters, which allows context-dependent attackers to obtain sensitive information from process stack memory by reading output from X509_name_oneline, X509_name_print_
debian
CVE-2013-6449P4MEDIUMCVSS 4.3fixed in openssl 1.0.1e-5 (bookworm)2013
CVE-2013-6449 [MEDIUM] CVE-2013-6449: openssl - The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains ... The ssl_get_algorithm2 function in ssl/s3_lib.c in OpenSSL before 1.0.2 obtains a certain version number from an incorrect data structure, which allows remote attackers to cause a denial of service (daemon crash) via crafted traffic from a TLS 1.2 client. Scope: local bookworm: resolved (fixed in 1.0.1e-5) bullseye: resolved (fixed in 1.0.1e-5) forky: resolved (fixe
debian
CVE-2022-2097P4MEDIUMCVSS 5.3fixed in openssl 3.0.5-1 (bookworm)2022
CVE-2022-2097 [MEDIUM] CVE-2022-2097: openssl - AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implem... AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does
debian
CVE-2011-3207P4MEDIUMCVSS 5.0fixed in openssl 1.0.0e-1 (bookworm)2011
CVE-2011-3207 [MEDIUM] CVE-2011-3207: openssl - crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certai... crypto/x509/x509_vfy.c in OpenSSL 1.0.x before 1.0.0e does not initialize certain structure members, which makes it easier for remote attackers to bypass CRL validation by using a nextUpdate value corresponding to a time in the past. Scope: local bookworm: resolved (fixed in 1.0.0e-1) bullseye: resolved (fixed in 1.0.0e-1) forky: resolved (fixed in 1.0.0e-1) sid: re
debian
CVE-2011-4619P4MEDIUMCVSS 5.0fixed in openssl 1.0.0h-1 (bookworm)2011
CVE-2011-4619 [MEDIUM] CVE-2011-4619: openssl - The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and ... The Server Gated Cryptography (SGC) implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly handle handshake restarts, which allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors. Scope: local bookworm: resolved (fixed in 1.0.0h-1) bullseye: resolved (fixed in 1.0.0h-1) forky: resolved (fixed in 1.0.0h
debian
CVE-2004-0079P4HIGHCVSS 7.5fixed in openssl 0.9.7d-1 (bookworm)2004
CVE-2004-0079 [HIGH] CVE-2004-0079: openssl - The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.... The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference. Scope: local bookworm: resolved (fixed in 0.9.7d-1) bullseye: resolved (fixed in 0.9.7d-1) forky: resolved (fixed in 0.9.7d-1) sid: resolved (fixed in 0.9.7d
debian
CVE-2002-0657P4HIGHCVSS 7.5fixed in openssl 0.9.6e-1 (bookworm)2002
CVE-2002-0657 [HIGH] CVE-2002-0657: openssl - Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allo... Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key. Scope: local bookworm: resolved (fixed in 0.9.6e-1) bullseye: resolved (fixed in 0.9.6e-1) forky: resolved (fixed in 0.9.6e-1) sid: resolved (fixed in 0.9.6e-1) trixie: resolved (fixed in 0.9.6e-1)
debian
CVE-2011-4576P4MEDIUMCVSS 5.0fixed in openssl 1.0.0f-1 (bookworm)2011
CVE-2011-4576 [MEDIUM] CVE-2011-4576: openssl - The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does n... The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly initialize data structures for block cipher padding, which might allow remote attackers to obtain sensitive information by decrypting the padding data sent by an SSL peer. Scope: local bookworm: resolved (fixed in 1.0.0f-1) bullseye: resolved (fixed in 1.0.0f-1) forky: resolv
debian
CVE-2015-0289P4MEDIUMCVSS 5.0fixed in openssl 1.0.1k-2 (bookworm)2015
CVE-2015-0289 [MEDIUM] CVE-2015-0289: openssl - The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 ... The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly handle a lack of outer ContentInfo, which allows attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an application that processes arbitrary PKCS#7 data and providing malformed data
debian
CVE-2013-0166P4MEDIUMCVSS 5.0fixed in openssl 1.0.1e-1 (bookworm)2013
CVE-2013-0166 [MEDIUM] CVE-2013-0166: openssl - OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not pro... OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key. Scope: local bookworm: resolved (fixed in 1.0.1e-1) bullseye: resolved (fixed in 1.0.1e-1) forky: re
debian
CVE-2023-3446P4MEDIUMCVSS 5.3fixed in openssl 3.0.10-1~deb12u1 (bookworm)2023
CVE-2023-3446 [MEDIUM] CVE-2023-3446: openssl - Issue summary: Checking excessively long DH keys or parameters may be very slow.... Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial
debian
CVE-2014-3569P4MEDIUMCVSS 4.3fixed in openssl 1.0.1k-1 (bookworm)2014
CVE-2014-3569 [MEDIUM] CVE-2014-3569: openssl - The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 0.9.8zc, 1.0.0o, an... The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 0.9.8zc, 1.0.0o, and 1.0.1j does not properly handle attempts to use unsupported protocols, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unexpected handshake, as demonstrated by an SSLv3 handshake to a no-ssl3 application with certain error h
debian
CVE-2011-4354P4MEDIUMCVSS 5.8fixed in openssl 0.9.8o-4squeeze3 (bookworm)2011
CVE-2011-4354 [MEDIUM] CVE-2011-4354: openssl - crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stu... crypto/bn/bn_nist.c in OpenSSL before 0.9.8h on 32-bit platforms, as used in stunnel and other products, in certain circumstances involving ECDH or ECDHE cipher suites, uses an incorrect modular reduction algorithm in its implementation of the P-256 and P-384 NIST elliptic curves, which allows remote attackers to obtain the private key of a TLS server via multiple h
debian
CVE-2024-9143P4MEDIUMCVSS 4.3fixed in openssl 3.0.15-1~deb12u1 (bookworm)2024
CVE-2024-9143 [MEDIUM] CVE-2024-9143: openssl - Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted e... Issue summary: Use of the low-level GF(2^m) elliptic curve APIs with untrusted explicit values for the field polynomial can lead to out-of-bounds memory reads or writes. Impact summary: Out of bound memory writes can lead to an application crash or even a possibility of a remote code execution, however, in all the protocols involving Elliptic Curve Cryptography that
debian
CVE-2025-4575P4LOWCVSS 6.5fixed in openssl 3.5.0-2 (forky)2025
CVE-2025-4575 [MEDIUM] CVE-2025-4575: openssl - Issue summary: Use of -addreject option with the openssl x509 application adds a... Issue summary: Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead marked as trusted for that use. A copy & paste error during minor refactoring of the code introduced this issue in th
debian
CVE-2025-15468P4LOWCVSS 5.9fixed in openssl 3.5.5-1 (forky)2025
CVE-2025-15468 [MEDIUM] CVE-2025-15468: openssl - Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC ... Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs. Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service. Some applications call SSL_CIPHER_find() from the client_hello
debian
CVE-2025-66199P4LOWCVSS 5.9fixed in openssl 3.5.5-1 (forky)2025
CVE-2025-66199 [MEDIUM] CVE-2025-66199: openssl - Issue summary: A TLS 1.3 connection using certificate compression can be forced ... Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit. Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resour
debian
CVE-2002-0655P4HIGHCVSS 7.5fixed in openssl 0.9.6e-1 (bookworm)2002
CVE-2002-0655 [HIGH] CVE-2002-0655: openssl - OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handl... OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code. Scope: local bookworm: resolved (fixed in 0.9.6e-1) bullseye: resolved (fixed in 0.9.6e-1) forky: resolved (fixed in 0.9.6e-1) sid: resolve
debian
CVE-2015-0287P4MEDIUMCVSS 5.0fixed in openssl 1.0.1k-2 (bookworm)2015
CVE-2015-0287 [MEDIUM] CVE-2015-0287: openssl - The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8z... The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure
debian
Debian OpenSSL vulnerabilities | cvebase