CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93126  CVE-2016-6306  Candidate  The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.  Assigned (20160726)  None (candidate not yet proposed)    View
93127  CVE-2016-6307  Candidate  The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c.  Assigned (20160726)  None (candidate not yet proposed)    View
93128  CVE-2016-6308  Candidate  statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted DTLS messages.  Assigned (20160726)  None (candidate not yet proposed)    View
93129  CVE-2016-6309  Candidate  statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.  Assigned (20160726)  None (candidate not yet proposed)    View
93130  CVE-2016-6310  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160726)  None (candidate not yet proposed)    View

Page 18626 of 20943, showing 5 records out of 104715 total, starting on record 93126, ending on 93130

Actions