7.5
CVSSv2

CVE-2010-0742

Published: 03/06/2010 Updated: 19/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Cryptographic Message Syntax (CMS) implementation in crypto/cms/cms_asn1.c in OpenSSL prior to 0.9.8o and 1.x prior to 1.0.0a does not properly handle structures that contain OriginatorInfo, which allows context-dependent malicious users to modify invalid memory locations or conduct double-free attacks, and possibly execute arbitrary code, via unspecified vectors.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openssl openssl 0.9.5a

openssl openssl 0.9.6a

openssl openssl 0.9.6i

openssl openssl 0.9.6h

openssl openssl 0.9.7

openssl openssl 0.9.1c

openssl openssl 0.9.8l

openssl openssl 0.9.8i

openssl openssl 0.9.7i

openssl openssl 0.9.7f

openssl openssl 0.9.8c

openssl openssl 0.9.8b

openssl openssl 0.9.5

openssl openssl 0.9.6

openssl openssl 0.9.6g

openssl openssl 0.9.6f

openssl openssl 0.9.3

openssl openssl 0.9.2b

openssl openssl 0.9.7a

openssl openssl 0.9.7c

openssl openssl 0.9.7h

openssl openssl 0.9.7k

openssl openssl 0.9.8e

openssl openssl 0.9.3a

openssl openssl 0.9.6c

openssl openssl 0.9.6b

openssl openssl 0.9.6k

openssl openssl 0.9.6j

openssl openssl 0.9.8h

openssl openssl 0.9.8m

openssl openssl 0.9.7d

openssl openssl 0.9.8j

openssl openssl 0.9.7g

openssl openssl 0.9.8

openssl openssl 0.9.8g

openssl openssl 0.9.8f

openssl openssl 0.9.7l

openssl openssl 0.9.4

openssl openssl 0.9.6e

openssl openssl 0.9.6d

openssl openssl 0.9.6m

openssl openssl 0.9.6l

openssl openssl 0.9.8k

openssl openssl 0.9.7m

openssl openssl 0.9.7e

openssl openssl 0.9.7b

openssl openssl 0.9.8a

openssl openssl 0.9.7j

openssl openssl 0.9.8d

openssl openssl

openssl openssl 1.0.0