← Back

Openssl

openssl

287 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Openssl
openssl

CVEs (287)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Apple
OpensslOracle
5Application Server
Corporate Time Outlook ConnectorHttp Server+2 more
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
1Openssl
1Openssl
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in OpenSSL 0.9.7 before 0.9.7-beta3, with Kerberos enabled, allows attackers to execute arbitrary code via a long master key.
3Apple
OpensslOracle
5Application Server
Corporate Time Outlook ConnectorHttp Server+2 more
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
3Apple
OpensslOracle
5Application Server
Corporate Time Outlook ConnectorHttp Server+2 more
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbit...Show more
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.Show less
2Openssl
Ssleay
2Openssl
Ssleay
Apr 16, 2026
Jul 10, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used by attackers to pre...Show more
The Pseudo-Random Number Generator (PRNG) in SSLeay and OpenSSL before 0.9.6b allows attackers to use the output of small PRNG requests to determine the internal state information, which could be used by attackers to predict future pseudo-random numbers.Show less
2Freebsd
Openssl
2Freebsd
Openssl
Apr 16, 2026
Jun 12, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be mor...Show more
OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.Show less
1Openssl
1Openssl
Apr 16, 2026
Mar 22, 1999
N/A· v4
N/A· v3
7.5 HIGH· v2
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.