NVD
- Id
- 18405
- Name
- CVE-2016-2108
- Description
- The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.
- Reject
- CVSS Version
- 2
- CVSS Score
- 10
- Severity
- High
- CVSS Base Score
- 10
- CVSS Impact Subscore
- 10
- CVSS Exploit Subscore
- 10
- CVSS Vector
- (AV:N/AC:L/Au:N/C:C/I:C/A:C)
- Pub Date
- 2017-06-12
- Published
- 2016-05-04
- Modified Date
- 2017-06-08
- Seq
- 2016-2108
Related NVD References
Id | NVD Id | NVD No. | Reference | Actions |
---|---|---|---|---|
101959 | 18405 | CVE-2016-2108 | http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759 | View |
101960 | 18405 | CVE-2016-2108 | APPLE-SA-2016-07-18-1 | View |
101961 | 18405 | CVE-2016-2108 | FEDORA-2016-05c567df1a | View |
101962 | 18405 | CVE-2016-2108 | FEDORA-2016-1411324654 | View |
101963 | 18405 | CVE-2016-2108 | FEDORA-2016-1e39d934ed | View |
101964 | 18405 | CVE-2016-2108 | SUSE-SU-2016:1206 | View |
101965 | 18405 | CVE-2016-2108 | SUSE-SU-2016:1228 | View |
101966 | 18405 | CVE-2016-2108 | SUSE-SU-2016:1231 | View |
101967 | 18405 | CVE-2016-2108 | SUSE-SU-2016:1233 | View |
101968 | 18405 | CVE-2016-2108 | openSUSE-SU-2016:1237 | View |
101969 | 18405 | CVE-2016-2108 | openSUSE-SU-2016:1238 | View |
101970 | 18405 | CVE-2016-2108 | openSUSE-SU-2016:1239 | View |
101971 | 18405 | CVE-2016-2108 | openSUSE-SU-2016:1240 | View |
101972 | 18405 | CVE-2016-2108 | openSUSE-SU-2016:1241 | View |
101973 | 18405 | CVE-2016-2108 | openSUSE-SU-2016:1242 | View |
101974 | 18405 | CVE-2016-2108 | openSUSE-SU-2016:1243 | View |
101975 | 18405 | CVE-2016-2108 | SUSE-SU-2016:1267 | View |
101976 | 18405 | CVE-2016-2108 | openSUSE-SU-2016:1273 | View |
101977 | 18405 | CVE-2016-2108 | SUSE-SU-2016:1290 | View |
101978 | 18405 | CVE-2016-2108 | SUSE-SU-2016:1360 | View |
101979 | 18405 | CVE-2016-2108 | http://packetstormsecurity.com/files/136912/Slackware-Security-Advisory-openssl-Updates.html | View |
101980 | 18405 | CVE-2016-2108 | RHSA-2016:0722 | View |
101981 | 18405 | CVE-2016-2108 | RHSA-2016:0996 | View |
101982 | 18405 | CVE-2016-2108 | http://source.android.com/security/bulletin/2016-07-01.html | View |
101983 | 18405 | CVE-2016-2108 | http://support.citrix.com/article/CTX212736 | View |
101984 | 18405 | CVE-2016-2108 | 20160504 Multiple Vulnerabilities in OpenSSL Affecting Cisco Products: May 2016 | View |
101985 | 18405 | CVE-2016-2108 | DSA-3566 | View |
101986 | 18405 | CVE-2016-2108 | http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html | View |
101987 | 18405 | CVE-2016-2108 | http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html | View |
101988 | 18405 | CVE-2016-2108 | http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html | View |
101989 | 18405 | CVE-2016-2108 | 89752 | View |
101990 | 18405 | CVE-2016-2108 | 91787 | View |
101991 | 18405 | CVE-2016-2108 | 1035721 | View |
101992 | 18405 | CVE-2016-2108 | SSA:2016-124-01 | View |
101993 | 18405 | CVE-2016-2108 | USN-2959-1 | View |
101994 | 18405 | CVE-2016-2108 | RHSA-2016:1137 | View |
101995 | 18405 | CVE-2016-2108 | https://bto.bluecoat.com/security-advisory/sa123 | View |
101996 | 18405 | CVE-2016-2108 | https://git.openssl.org/?p=openssl.git;a=commit;h=3661bb4e7934668bd99ca777ea8b30eedfafa871 | View |
101997 | 18405 | CVE-2016-2108 | https://git.openssl.org/?p=openssl.git;a=commit;h=f5da52e308a6aeea6d5f3df98c4da295d7e9cc27 | View |
101998 | 18405 | CVE-2016-2108 | https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05149345 | View |
101999 | 18405 | CVE-2016-2108 | https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05164862 | View |
102000 | 18405 | CVE-2016-2108 | https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA40202 | View |
102001 | 18405 | CVE-2016-2108 | https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00067&languageid=en-fr | View |
102002 | 18405 | CVE-2016-2108 | GLSA-201612-16 | View |
102003 | 18405 | CVE-2016-2108 | https://support.apple.com/HT206903 | View |
102004 | 18405 | CVE-2016-2108 | https://www.openssl.org/news/secadv/20160503.txt | View |
Related JVN
Id | Name | Title | Summary | Cveinfo Name | Cveinfo Id | Nvdinfo Name | Nvdinfo Id | Cvssv2 | Cvssv3 | Jvnurl | Published Date | Last Updated Date | Actions |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1702 | JVNDB-2016-002475 | OpenSSL の ASN.1 の実装における任意のコードを実行される脆弱性 | OpenSSL の ASN.1 の実装には、任意のコードを実行される、またはサービス運用妨害 (バッファアンダーフローおよびメモリ破損) 状態にされる脆弱性が存在します。 | CVE-2016-2108 | 88614 | CVE-2016-2108 | 18405 | 10 | 9.8 | http://jvndb.jvn.jp/ja/contents/2016/JVNDB-2016-002475.html | 2016-05-03 | 2016-11-22 | View |