Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
openssl vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2020-28018
Exim 4 prior to 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.
Exim Exim
2 Github repositories
9.8
CVSSv3
CVE-2020-25179
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
Gehealthcare 3.0t Signa Hdxt Firmware -
Gehealthcare 3.0t Signa Hd 16 Firmware -
Gehealthcare 3.0t Signa Hd 23 Firmware -
Gehealthcare 1.5t Brivo Mr355 Firmware -
Gehealthcare Optima Mr360 Firmware -
Gehealthcare Signa Hdi 1.5t Firmware -
Gehealthcare Signa Vibrant Firmware -
Gehealthcare Logiq 5 Bt03 Firmware -
Gehealthcare Logiq 7 Bt03 Firmware -
Gehealthcare Logiq 7 Bt04 Firmware -
Gehealthcare Logiq 7 Bt06 Firmware -
Gehealthcare Logiq 9 Bt02 Firmware -
Gehealthcare Logiq 9 Bt03 Firmware -
Gehealthcare Logiq 9 Bt04 Firmware -
Gehealthcare Logiq 9 Bt06 Firmware -
Gehealthcare Vivid I Bt06 Firmware -
Gehealthcare Vivid 7 Bt02 Firmware -
Gehealthcare Vivid 7 Bt06 Firmware -
Gehealthcare Echopac Bt06 Firmware -
Gehealthcare Image Vault Firmware -
Gehealthcare Voluson 730 Bt05 Firmware -
Gehealthcare Voluson 730 Bt08 Firmware -
1 Article
9.8
CVSSv3
CVE-2020-24714
The Scalyr Agent prior to 2.1.10 has Missing SSL Certificate Validation because, in some circumstances, the openssl binary is called without the -verify_hostname option.
Scalyr Scalyr Agent
9.8
CVSSv3
CVE-2020-13417
An Elevation of Privilege issue exists in Aviatrix VPN Client prior to 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.
Aviatrix Controller
Aviatrix Gateway
Aviatrix Vpn Client
9.8
CVSSv3
CVE-2020-7224
The Aviatrix OpenVPN client up to and including 2.5.7 on Linux, macOS, and Windows is vulnerable when OpenSSL parameters are altered from the issued value set; the parameters could allow unauthorized third-party libraries to load.
Aviatrix Openvpn
9.8
CVSSv3
CVE-2011-4121
The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used for private RSA key generation. A remote attacker could use this flaw to bypass or corrupt integrity of services, depending on stron...
Ruby-lang Ruby
9.8
CVSSv3
CVE-2019-10211
Postgresql Windows installer prior to 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
Postgresql Postgresql
9.8
CVSSv3
CVE-2018-20997
An issue exists in the openssl crate prior to 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
Rust-openssl Project Rust-openssl
1 Github repository
9.8
CVSSv3
CVE-2018-7584
In PHP up to and including 5.6.33, 7.0.x prior to 7.0.28, 7.1.x up to and including 7.1.14, and 7.2.x up to and including 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper....
Php Php
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 17.10
Canonical Ubuntu Linux 12.04
Canonical Ubuntu Linux 16.04
Debian Debian Linux 7.0
Debian Debian Linux 8.0
Debian Debian Linux 9.0
1 EDB exploit
9.8
CVSSv3
CVE-2015-5244
The NSSCipherSuite option with ciphersuites enabled in mod_nss prior to 1.0.12 allows remote malicious users to bypass application restrictions.
Mod Nss Project Mod Nss
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »