Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2016-6307

The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.188
EPSS Ranking 95.0%
CVSS Severity
CVSS v3 Score 5.9
CVSS v2 Score 4.3
References
Products affected by CVE-2016-6307
  • Openssl » Openssl » Version: 1.1.0
    cpe:2.3:a:openssl:openssl:1.1.0


Contact Us

Shodan ® - All rights reserved