Vulnerability Database

296,172

Total vulnerabilities in the database

CVE-2009-3245

OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.

  • Published: Mar 5, 2010
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-3245
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 10
  • AV:N/AC:L/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
openssl / openssl 0.9.8b 0.9.8b.x
openssl / openssl - 0.9.8l.x
openssl / openssl 0.9.8c 0.9.8c.x
openssl / openssl 0.9.8e 0.9.8e.x
openssl / openssl 0.9.8g 0.9.8g.x
openssl / openssl 0.9.8k 0.9.8k.x
openssl / openssl 0.9.8d 0.9.8d.x
openssl / openssl 0.9.8j 0.9.8j.x
openssl / openssl 0.9.8a 0.9.8a.x
openssl / openssl 0.9.8 0.9.8.x
openssl / openssl 0.9.8i 0.9.8i.x
openssl / openssl 0.9.8f 0.9.8f.x
openssl / openssl 0.9.8h 0.9.8h.x