VDB

DEBIAN-CVE-2014-3566

DEBIAN-CVE-2014-3566 PUBLISHED CVSS 3.4000000953674316 LOW

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

Risk Scores

CVSS v3.1
3.4000000953674316
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N

Affected Products

VendorProductVersions
Debian:14lighttpd0, 0, 0
Debian:11netsurf0, 0, 0
Debian:12erlang0, 0, 0
Debian:14nss0, 0, 0
Debian:13netsurf0, 0, 0
Debian:14pound0, 0, 0
Debian:14netsurf0, 0, 0
Debian:12netsurf0, 0, 0
Debian:12epiphany-browser48.5-2, 44.5-1, 44.5-2
Debian:11openssl0, 0, 0
Debian:13haskell-tls0, 0, 0
Debian:12lighttpd0, 0, 0
Debian:11wolfssl0, 0, 0
Debian:13pound0, 0, 0
Debian:14epiphany-browser48.5-2, 48.5-3, 49.1-1
Debian:13wolfssl0, 0, 0
Debian:12gnutls280, 0, 0
Debian:12openssl0, 0, 0
Debian:13erlang0, 0, 0
Debian:13gnutls280, 0, 0

…and 24 more

Timeline

  • Oct 15, 2014 CVE Published
  • Oct 21, 2014 PoC Published
  • Apr 11, 2025 PoC Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›