Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-0195

The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS ClientHello messages, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a long non-initial fragment.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.909
EPSS Ranking 99.6%
CVSS Severity
CVSS v2 Score 6.8
References
Products affected by CVE-2014-0195
  • Mariadb » Mariadb » Version: 10.0.0
    cpe:2.3:a:mariadb:mariadb:10.0.0
  • Mariadb » Mariadb » Version: 10.0.1
    cpe:2.3:a:mariadb:mariadb:10.0.1
  • Mariadb » Mariadb » Version: 10.0.10
    cpe:2.3:a:mariadb:mariadb:10.0.10
  • Mariadb » Mariadb » Version: 10.0.11
    cpe:2.3:a:mariadb:mariadb:10.0.11
  • Mariadb » Mariadb » Version: 10.0.12
    cpe:2.3:a:mariadb:mariadb:10.0.12
  • Mariadb » Mariadb » Version: 10.0.2
    cpe:2.3:a:mariadb:mariadb:10.0.2
  • Mariadb » Mariadb » Version: 10.0.3
    cpe:2.3:a:mariadb:mariadb:10.0.3
  • Mariadb » Mariadb » Version: 10.0.4
    cpe:2.3:a:mariadb:mariadb:10.0.4
  • Mariadb » Mariadb » Version: 10.0.5
    cpe:2.3:a:mariadb:mariadb:10.0.5
  • Mariadb » Mariadb » Version: 10.0.6
    cpe:2.3:a:mariadb:mariadb:10.0.6
  • Mariadb » Mariadb » Version: 10.0.7
    cpe:2.3:a:mariadb:mariadb:10.0.7
  • Mariadb » Mariadb » Version: 10.0.8
    cpe:2.3:a:mariadb:mariadb:10.0.8
  • Mariadb » Mariadb » Version: 10.0.9
    cpe:2.3:a:mariadb:mariadb:10.0.9
  • Openssl » Openssl » Version: 0.9.8
    cpe:2.3:a:openssl:openssl:0.9.8
  • Openssl » Openssl » Version: 0.9.8a
    cpe:2.3:a:openssl:openssl:0.9.8a
  • Openssl » Openssl » Version: 0.9.8b
    cpe:2.3:a:openssl:openssl:0.9.8b
  • Openssl » Openssl » Version: 0.9.8c
    cpe:2.3:a:openssl:openssl:0.9.8c
  • Openssl » Openssl » Version: 0.9.8c-1
    cpe:2.3:a:openssl:openssl:0.9.8c-1
  • Openssl » Openssl » Version: 0.9.8d
    cpe:2.3:a:openssl:openssl:0.9.8d
  • Openssl » Openssl » Version: 0.9.8e
    cpe:2.3:a:openssl:openssl:0.9.8e
  • Openssl » Openssl » Version: 0.9.8f
    cpe:2.3:a:openssl:openssl:0.9.8f
  • Openssl » Openssl » Version: 0.9.8g
    cpe:2.3:a:openssl:openssl:0.9.8g
  • Openssl » Openssl » Version: 0.9.8g-9
    cpe:2.3:a:openssl:openssl:0.9.8g-9
  • Openssl » Openssl » Version: 0.9.8h
    cpe:2.3:a:openssl:openssl:0.9.8h
  • Openssl » Openssl » Version: 0.9.8i
    cpe:2.3:a:openssl:openssl:0.9.8i
  • Openssl » Openssl » Version: 0.9.8j
    cpe:2.3:a:openssl:openssl:0.9.8j
  • Openssl » Openssl » Version: 0.9.8k
    cpe:2.3:a:openssl:openssl:0.9.8k
  • Openssl » Openssl » Version: 0.9.8l
    cpe:2.3:a:openssl:openssl:0.9.8l
  • Openssl » Openssl » Version: 0.9.8m
    cpe:2.3:a:openssl:openssl:0.9.8m
  • Openssl » Openssl » Version: 0.9.8n
    cpe:2.3:a:openssl:openssl:0.9.8n
  • Openssl » Openssl » Version: 0.9.8o
    cpe:2.3:a:openssl:openssl:0.9.8o
  • Openssl » Openssl » Version: 0.9.8p
    cpe:2.3:a:openssl:openssl:0.9.8p
  • Openssl » Openssl » Version: 0.9.8q
    cpe:2.3:a:openssl:openssl:0.9.8q
  • Openssl » Openssl » Version: 0.9.8r
    cpe:2.3:a:openssl:openssl:0.9.8r
  • Openssl » Openssl » Version: 0.9.8s
    cpe:2.3:a:openssl:openssl:0.9.8s
  • Openssl » Openssl » Version: 0.9.8t
    cpe:2.3:a:openssl:openssl:0.9.8t
  • Openssl » Openssl » Version: 0.9.8u
    cpe:2.3:a:openssl:openssl:0.9.8u
  • Openssl » Openssl » Version: 0.9.8v
    cpe:2.3:a:openssl:openssl:0.9.8v
  • Openssl » Openssl » Version: 0.9.8w
    cpe:2.3:a:openssl:openssl:0.9.8w
  • Openssl » Openssl » Version: 0.9.8x
    cpe:2.3:a:openssl:openssl:0.9.8x
  • Openssl » Openssl » Version: 0.9.8y
    cpe:2.3:a:openssl:openssl:0.9.8y
  • Openssl » Openssl » Version: 0.9.8z
    cpe:2.3:a:openssl:openssl:0.9.8z
  • Openssl » Openssl » Version: 1.0.0
    cpe:2.3:a:openssl:openssl:1.0.0
  • Openssl » Openssl » Version: 1.0.0a
    cpe:2.3:a:openssl:openssl:1.0.0a
  • Openssl » Openssl » Version: 1.0.0b
    cpe:2.3:a:openssl:openssl:1.0.0b
  • Openssl » Openssl » Version: 1.0.0c
    cpe:2.3:a:openssl:openssl:1.0.0c
  • Openssl » Openssl » Version: 1.0.0d
    cpe:2.3:a:openssl:openssl:1.0.0d
  • Openssl » Openssl » Version: 1.0.0e
    cpe:2.3:a:openssl:openssl:1.0.0e
  • Openssl » Openssl » Version: 1.0.0f
    cpe:2.3:a:openssl:openssl:1.0.0f
  • Openssl » Openssl » Version: 1.0.0g
    cpe:2.3:a:openssl:openssl:1.0.0g
  • Openssl » Openssl » Version: 1.0.0h
    cpe:2.3:a:openssl:openssl:1.0.0h
  • Openssl » Openssl » Version: 1.0.0i
    cpe:2.3:a:openssl:openssl:1.0.0i
  • Openssl » Openssl » Version: 1.0.0j
    cpe:2.3:a:openssl:openssl:1.0.0j
  • Openssl » Openssl » Version: 1.0.0k
    cpe:2.3:a:openssl:openssl:1.0.0k
  • Openssl » Openssl » Version: 1.0.0l
    cpe:2.3:a:openssl:openssl:1.0.0l
  • Openssl » Openssl » Version: 1.0.1
    cpe:2.3:a:openssl:openssl:1.0.1
  • Openssl » Openssl » Version: 1.0.1a
    cpe:2.3:a:openssl:openssl:1.0.1a
  • Openssl » Openssl » Version: 1.0.1b
    cpe:2.3:a:openssl:openssl:1.0.1b
  • Openssl » Openssl » Version: 1.0.1c
    cpe:2.3:a:openssl:openssl:1.0.1c
  • Openssl » Openssl » Version: 1.0.1d
    cpe:2.3:a:openssl:openssl:1.0.1d
  • Openssl » Openssl » Version: 1.0.1e
    cpe:2.3:a:openssl:openssl:1.0.1e
  • Openssl » Openssl » Version: 1.0.1f
    cpe:2.3:a:openssl:openssl:1.0.1f
  • Openssl » Openssl » Version: 1.0.1g
    cpe:2.3:a:openssl:openssl:1.0.1g
  • Fedoraproject » Fedora » Version: 19
    cpe:2.3:o:fedoraproject:fedora:19
  • Fedoraproject » Fedora » Version: 20
    cpe:2.3:o:fedoraproject:fedora:20
  • Opensuse » Leap » Version: 42.1
    cpe:2.3:o:opensuse:leap:42.1
  • Opensuse » Opensuse » Version: 13.2
    cpe:2.3:o:opensuse:opensuse:13.2


Contact Us

Shodan ® - All rights reserved