OpenSSL
TLS/SSL and cryptography toolkit.
Source repositories
CVEs (384)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2001-0361 | 0.00 | — | 0.03 | Jun 27, 2001 | Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5. | |||
| CVE-2001-1459 | 0.00 | — | 0.02 | Jun 19, 2001 | OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d. | |||
| CVE-2000-0535 | 0.00 | — | 0.01 | Jun 12, 2000 | OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken. | |||
| CVE-1999-0428 | 0.00 | — | 0.03 | Mar 22, 1999 | OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls. |
- CVE-2001-0361Jun 27, 2001risk 0.00cvss —epss 0.03
Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5.
- CVE-2001-1459Jun 19, 2001risk 0.00cvss —epss 0.02
OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.
- CVE-2000-0535Jun 12, 2000risk 0.00cvss —epss 0.01
OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.
- CVE-1999-0428Mar 22, 1999risk 0.00cvss —epss 0.03
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
Page 20 of 20