Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2011-0014

ssl/t1_lib.c in OpenSSL 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c allows remote attackers to cause a denial of service (crash), and possibly obtain sensitive information in applications that use OpenSSL, via a malformed ClientHello handshake message that triggers an out-of-bounds memory access, aka "OCSP stapling vulnerability."
Exploit prediction scoring system (EPSS) score
EPSS Score 0.017
EPSS Ranking 81.7%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2011-0014
  • Openssl » Openssl » Version: 0.9.8h
    cpe:2.3:a:openssl:openssl:0.9.8h
  • Openssl » Openssl » Version: 0.9.8i
    cpe:2.3:a:openssl:openssl:0.9.8i
  • Openssl » Openssl » Version: 0.9.8j
    cpe:2.3:a:openssl:openssl:0.9.8j
  • Openssl » Openssl » Version: 0.9.8k
    cpe:2.3:a:openssl:openssl:0.9.8k
  • Openssl » Openssl » Version: 0.9.8l
    cpe:2.3:a:openssl:openssl:0.9.8l
  • Openssl » Openssl » Version: 0.9.8m
    cpe:2.3:a:openssl:openssl:0.9.8m
  • Openssl » Openssl » Version: 0.9.8n
    cpe:2.3:a:openssl:openssl:0.9.8n
  • Openssl » Openssl » Version: 0.9.8o
    cpe:2.3:a:openssl:openssl:0.9.8o
  • Openssl » Openssl » Version: 0.9.8p
    cpe:2.3:a:openssl:openssl:0.9.8p
  • Openssl » Openssl » Version: 0.9.8q
    cpe:2.3:a:openssl:openssl:0.9.8q
  • Openssl » Openssl » Version: 1.0.0
    cpe:2.3:a:openssl:openssl:1.0.0
  • Openssl » Openssl » Version: 1.0.0a
    cpe:2.3:a:openssl:openssl:1.0.0a
  • Openssl » Openssl » Version: 1.0.0b
    cpe:2.3:a:openssl:openssl:1.0.0b
  • Openssl » Openssl » Version: 1.0.0c
    cpe:2.3:a:openssl:openssl:1.0.0c


Contact Us

Shodan ® - All rights reserved