VDB
CVE-2004-0081
CVE-2004-0081
PUBLISHED
CVSS 5 MEDIUM
OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.
EPSS 7.23% · 93.7th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
7.23%
93.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openbsd | openbsd | 3.3, 3.4 |
| hp | apache-based_web_server | 2.0.43.04, 2.0.43.00 |
| cisco | access_registrar | |
| securecomputing | sidewinder | 5.2.0.01, 5.2.1.02, 5.2.0.03 |
| hp | wbem | a.01.05.08, a.02.00.00, * |
| checkpoint | vpn-1 | next_generation_fp1, next_generation, next_generation_fp0 |
| stonesoft | stonebeat_webcluster | 2.5, 2.0 |
| apple | mac_os_x_server | 10.3.3 |
| cisco | threat_response | |
| dell | bsafe_ssl-j | 3.0, 3.1, 3.0.1 |
| cisco | ciscoworks_common_services | 2.2 |
| avaya | sg5 | 4.2, 4.3, 4.4 |
| apple | mac_os_x | 10.3.3 |
| redhat | enterprise_linux | 3.0, 3.0, 3.0 |
| avaya | intuity_audix | *, 5.1.46, * |
| avaya | converged_communications_server | 2.0 |
| cisco | css_secure_content_accelerator | 2.0, 1.0 |
| neoteris | instant_virtual_extranet | 3.2, 3.3.1, 3.0 |
| stonesoft | stonegate_vpn_client | 2.0.9, 2.0.8, 2.0.7 |
| cisco | application_and_content_networking_software |
…and 47 more
Timeline
- Jul 18, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- 9899 vdb
- 20040317 Re: New OpenSSL releases fix denial of service attacks [17 March 2004] mailing-list
- openssl-tls-dos(15509) vdb
- http://www.uniras.gov.uk/vuls/2004/224012/index.htm url
- oval:org.mitre.oval:def:871 vdb
- GLSA-200403-03 vendor-advisory
- 20040508 [FLSA-2004:1395] Updated OpenSSL resolves security vulnerability mailing-list
- 20040317 Cisco OpenSSL Implementation Vulnerability vendor-advisory
- DSA-465 vendor-advisory
- 20040304-01-U vendor-advisory
- oval:org.mitre.oval:def:902 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2004-0081 advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11755 url
- http://fedoranews.org/updates/FEDORA-2004-095.shtml url
- http://www.kb.cert.org/vuls/id/465542 url
- http://www.linuxsecurity.com/advisories/engarde_advisory-4135.html url
- http://www.redhat.com/support/errata/RHSA-2004-120.html url
- http://www.redhat.com/support/errata/RHSA-2004-139.html url
- http://rhn.redhat.com/errata/RHSA-2004-119.html technical
- http://www.us-cert.gov/cas/techalerts/TA04-078A.html advisory
…and 6 more