Total vulnerabilities in the database
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
Software | From | Fixed in |
---|---|---|
openssl / openssl | 1.0.0 | 1.0.0m |
openssl / openssl | 1.0.1 | 1.0.1h |
openssl / openssl | - | 0.9.8za |
redhat / jboss_enterprise_web_platform | 5.2.0 | 5.2.0.x |
redhat / enterprise_linux | 6.0 | 6.0.x |
redhat / storage | 2.1 | 2.1.x |
redhat / enterprise_linux | 4 | 4.x |
redhat / enterprise_linux | 5 | 5.x |
redhat / jboss_enterprise_web_server | 2.0.1 | 2.0.1.x |
redhat / jboss_enterprise_application_platform | 5.2.0 | 5.2.0.x |
fedoraproject / fedora | 20 | 20.x |
redhat / jboss_enterprise_application_platform | 6.2.3 | 6.2.3.x |
fedoraproject / fedora | 19 | 19.x |
opensuse / opensuse | 13.1 | 13.1.x |
opensuse / opensuse | 13.2 | 13.2.x |
filezilla-project / filezilla_server | - | 0.9.45 |
siemens / application_processing_engine_firmware | - | 2.0.2 |
siemens / cp1543-1_firmware | - | 1.1.25 |
siemens / s7-1500_firmware | - | 1.6 |
siemens / rox_firmware | - | 1.16.1 |
mariadb / mariadb | 10.0.0 | 10.0.13 |
python / python | 3.4.0 | 3.4.2 |
python / python | 2.7.0 | 2.7.8 |
nodejs / node.js | - | 0.10.29 |