CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
93126 | CVE-2016-6306 | Candidate | The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c. | Assigned (20160726) | None (candidate not yet proposed) | View | |
93127 | CVE-2016-6307 | Candidate | The state-machine implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted TLS messages, related to statem/statem.c and statem/statem_lib.c. | Assigned (20160726) | None (candidate not yet proposed) | View | |
93128 | CVE-2016-6308 | Candidate | statem/statem_dtls.c in the DTLS implementation in OpenSSL 1.1.0 before 1.1.0a allocates memory before checking for an excessive length, which might allow remote attackers to cause a denial of service (memory consumption) via crafted DTLS messages. | Assigned (20160726) | None (candidate not yet proposed) | View | |
93129 | CVE-2016-6309 | Candidate | statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session. | Assigned (20160726) | None (candidate not yet proposed) | View | |
93130 | CVE-2016-6310 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160726) | None (candidate not yet proposed) | View |
Page 18626 of 20943, showing 5 records out of 104715 total, starting on record 93126, ending on 93130