Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-5135

Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.306
EPSS Ranking 96.5%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2007-5135
  • Openssl » Openssl » Version: 0.9.7
    cpe:2.3:a:openssl:openssl:0.9.7
  • Openssl » Openssl » Version: 0.9.7a
    cpe:2.3:a:openssl:openssl:0.9.7a
  • Openssl » Openssl » Version: 0.9.7b
    cpe:2.3:a:openssl:openssl:0.9.7b
  • Openssl » Openssl » Version: 0.9.7c
    cpe:2.3:a:openssl:openssl:0.9.7c
  • Openssl » Openssl » Version: 0.9.7d
    cpe:2.3:a:openssl:openssl:0.9.7d
  • Openssl » Openssl » Version: 0.9.7e
    cpe:2.3:a:openssl:openssl:0.9.7e
  • Openssl » Openssl » Version: 0.9.7f
    cpe:2.3:a:openssl:openssl:0.9.7f
  • Openssl » Openssl » Version: 0.9.7g
    cpe:2.3:a:openssl:openssl:0.9.7g
  • Openssl » Openssl » Version: 0.9.7h
    cpe:2.3:a:openssl:openssl:0.9.7h
  • Openssl » Openssl » Version: 0.9.7i
    cpe:2.3:a:openssl:openssl:0.9.7i
  • Openssl » Openssl » Version: 0.9.7j
    cpe:2.3:a:openssl:openssl:0.9.7j
  • Openssl » Openssl » Version: 0.9.7k
    cpe:2.3:a:openssl:openssl:0.9.7k
  • Openssl » Openssl » Version: 0.9.7l
    cpe:2.3:a:openssl:openssl:0.9.7l
  • Openssl » Openssl » Version: 0.9.8
    cpe:2.3:a:openssl:openssl:0.9.8
  • Openssl » Openssl » Version: 0.9.8a
    cpe:2.3:a:openssl:openssl:0.9.8a
  • Openssl » Openssl » Version: 0.9.8b
    cpe:2.3:a:openssl:openssl:0.9.8b
  • Openssl » Openssl » Version: 0.9.8c
    cpe:2.3:a:openssl:openssl:0.9.8c
  • Openssl » Openssl » Version: 0.9.8d
    cpe:2.3:a:openssl:openssl:0.9.8d
  • Openssl » Openssl » Version: 0.9.8e
    cpe:2.3:a:openssl:openssl:0.9.8e
  • Openssl » Openssl » Version: 0.9.8f
    cpe:2.3:a:openssl:openssl:0.9.8f


Contact Us

Shodan ® - All rights reserved