Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2012-2131

Multiple integer signedness errors in crypto/buffer/buffer.c in OpenSSL 0.9.8v allow remote attackers to conduct buffer overflow attacks, and cause a denial of service (memory corruption) or possibly have unspecified other impact, via crafted DER data, as demonstrated by an X.509 certificate or an RSA public key. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2110.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.057
EPSS Ranking 90.0%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2012-2131
  • Openssl » Openssl » Version: 0.9.8v
    cpe:2.3:a:openssl:openssl:0.9.8v


Contact Us

Shodan ® - All rights reserved