Vulnerabilities
Vulnerable Software
Openssl:  >> Openssl  >> 0.9.8f  Security Vulnerabilities
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.
CVSS Score
7.5
EPSS Score
0.041
Published
2008-05-13
Off-by-one error in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 up to 0.9.7l, and 0.9.8 up to 0.9.8f, might allow remote attackers to execute arbitrary code via a crafted packet that triggers a one-byte buffer underflow. NOTE: this issue was introduced as a result of a fix for CVE-2006-3738. As of 20071012, it is unknown whether code execution is possible.
CVSS Score
6.8
EPSS Score
0.157
Published
2007-09-27


Contact Us

Shodan ® - All rights reserved