296,733
Total vulnerabilities in the database
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
| Software | From | Fixed in |
|---|---|---|
| openssl / openssl | 1.0.0 | 1.0.0m |
| openssl / openssl | 1.0.1 | 1.0.1h |
| openssl / openssl | - | 0.9.8za |
| redhat / jboss_enterprise_web_platform | 5.2.0 | 5.2.0.x |
| redhat / enterprise_linux | 6.0 | 6.0.x |
| redhat / storage | 2.1 | 2.1.x |
| redhat / enterprise_linux | 4 | 4.x |
| redhat / enterprise_linux | 5 | 5.x |
| redhat / jboss_enterprise_web_server | 2.0.1 | 2.0.1.x |
| redhat / jboss_enterprise_application_platform | 5.2.0 | 5.2.0.x |
| fedoraproject / fedora | 20 | 20.x |
| redhat / jboss_enterprise_application_platform | 6.2.3 | 6.2.3.x |
| fedoraproject / fedora | 19 | 19.x |
| opensuse / opensuse | 13.1 | 13.1.x |
| opensuse / opensuse | 13.2 | 13.2.x |
| filezilla-project / filezilla_server | - | 0.9.45 |
| siemens / application_processing_engine_firmware | - | 2.0.2 |
| siemens / cp1543-1_firmware | - | 1.1.25 |
| siemens / s7-1500_firmware | - | 1.6 |
| siemens / rox_firmware | - | 1.16.1 |
| mariadb / mariadb | 10.0.0 | 10.0.13 |
| python / python | 3.4.0 | 3.4.2 |
| python / python | 2.7.0 | 2.7.8 |
| nodejs / node.js | - | 0.10.29 |