VDB

CVE-2004-0112

CVE-2004-0112 PUBLISHED CVSS 5 MEDIUM

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

EPSS 0.92% · 76.3th percentile

Risk Scores

CVSS 2.0
5
EPSS Score
0.92%
76.3th percentile

Affected Products

VendorProductVersions
tarantellatarantella_enterprise3.20, 3.40, 3.30
n/an/an/a
novelledirectory8.5, 8.7, 8.5.27
securecomputingsidewinder5.2.0.02, 5.2.0.03, 5.2.0.04
ciscogss_4490_global_site_selector
stonesoftstonebeat_securitycluster2.5, 2.0
bluecoatcacheos_ca_sa4.1.12, 4.1.10
avayas8700r2.0.0, *
redhatopenssl0.9.6-15, 0.9.7a-2, 0.9.7a-2
suncrypto_accelerator_40001.0
ciscociscoworks_common_management_foundation2.1
avayasg54.3, 4.2, 4.4
stonesoftservercluster2.5, 2.5.2
novellimanager1.5, 2.0
ciscocall_manager
ciscoaccess_registrar
avayasg2034.4, 4.31.29
ciscookena_stormwatch3.2
ciscopix_firewall_software6.1\(5\), 6.0\(4.101\), 6.0
forcepointstonegate2.0.9, 1.5.17, 2.1

…and 46 more

Exploit Intelligence

…and 19 more exploits

Timeline

  • Jul 18, 2003 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Sep 8, 2023 EPSS Score

References

…and 10 more

Open in Interactive Console →
$ Console Community · 100/wk Open console ›