Shortened for this page: results: 3 of 25 shown; results[].references: first 10 items; results[].configurations[].nodes[].cpe_match: first 10 items; results[].enrichment.cpe: first 10 items; results[].enrichment.cwe[].capec_id: first 10 items
{
"page": 1,
"page_size": 25,
"result_count": 1452,
"results": [
{
"id": "CVE-2012-2568",
"source_identifier": "user@cert.org",
"published": "2012-05-25T20:55:01Z",
"last_modified": "2026-06-16T23:41:41Z",
"status": "Modified",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "d41d8cd98f00b204e9800998ecf8427e.php in the management web server on the Seagate BlackArmor device allows remote attackers to change the administrator password via unspecified vectors."
},
{
"lang": "es",
"value": "d41d8cd98f00b204e9800998ecf8427e.php en el servidor web de gestión en el dispositivo Seagate BlackArmor permite a atacantes remotos cambiar la contraseña de administrador a través de vectores no especificados."
}
],
"references": [
{
"url": "http://secunia.com/advisories/49282",
"source": "user@cert.org",
"tags": null
},
{
"url": "http://www.kb.cert.org/vuls/id/515283",
"source": "user@cert.org",
"tags": [
"US Government Resource"
]
},
{
"url": "http://www.securityfocus.com/bid/53670",
"source": "user@cert.org",
"tags": null
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75854",
"source": "user@cert.org",
"tags": null
},
{
"url": "http://secunia.com/advisories/49282",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
},
{
"url": "http://www.kb.cert.org/vuls/id/515283",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"US Government Resource"
]
},
{
"url": "http://www.securityfocus.com/bid/53670",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/75854",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": null,
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"access_vector": "NETWORK",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "COMPLETE",
"integrity_impact": "COMPLETE",
"availability_impact": "COMPLETE",
"base_score": 10.0,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "HIGH",
"exploitability_score": 10.0,
"impact_score": 10.0,
"ac_insuf_info": false,
"obtain_all_privilege": true,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:h:seagate:blackarmor_nas:*:*:*:*:*:*:*:*",
"match_criteria_id": "2EB0AAF0-1AAE-42A4-B6B2-5A4C75D2F2EE",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": [
{
"organization": "Seagate",
"comment": "The latest revision of the Seagate Software now includes a fix, which address the previously publicized security hole. We will be communicating this to our installed base of users both by direct email as well as Update notifications sent through the BlackArmor NAS User Interface. \n\nThe software updates can be found here: \nhttp://www.seagate.com/support/external-hard-drives/network-storage/blackarmor-nas-110/banas-110-firmware-master-dl/\nhttp://www.seagate.com/support/external-hard-drives/network-storage/blackarmor-nas-220/banas-220-firmware-master-dl/\nhttp://www.seagate.com/support/external-hard-drives/network-storage/blackarmor-nas-440/banas-440-firmware-master-dl/\n\n\n\nNote that there are 3 different versions of the firmware update, which correlate to the number of bays in the hardware (e.g 1-bay, 2-bay and 4-bay).",
"last_modified": "2012-10-26T00:00:00Z"
}
],
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:h:seagate:blackarmor_nas:*:*:*:*:*:*:*:*",
"vendor": "seagate",
"product": "blackarmor_nas",
"product_type": "h",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": null,
"affected_versions_last": null
}
],
"cwe": null,
"epss_score": {
"epss": 0.04422,
"percentile": 0.9093,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": null,
"user_interaction": null,
"vulnerable_system_confidentiality": "COMPLETE",
"vulnerable_system_integrity": "COMPLETE",
"vulnerable_system_availability": "COMPLETE",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 10.0,
"base_severity": "HIGH"
}
}
}
},
{
"id": "CVE-2009-4143",
"source_identifier": "user@redhat.com",
"published": "2009-12-21T16:30:00Z",
"last_modified": "2026-06-16T23:13:07Z",
"status": "Modified",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "PHP before 5.2.12 does not properly handle session data, which has unspecified impact and attack vectors related to (1) interrupt corruption of the SESSION superglobal array and (2) the session.save_path directive."
},
{
"lang": "es",
"value": "PHP versiones anteriores a v5.2.12 no maneja adecuadamente los datos de sesión, teniendo un impacto no especificado y vectores de ataque relacionado con (1) la interrupción de corrupción de la selección SESSION superglobal y (2) la directiva session.save_path."
}
],
"references": [
{
"url": "http://lists.apple.com/archives/security-announce/2010//Mar/msg00001.html",
"source": "user@redhat.com",
"tags": null
},
{
"url": "http://marc.info/?l=bugtraq&m=127680701405735&w=2",
"source": "user@redhat.com",
"tags": null
},
{
"url": "http://secunia.com/advisories/37821",
"source": "user@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/38648",
"source": "user@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/40262",
"source": "user@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/41480",
"source": "user@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://secunia.com/advisories/41490",
"source": "user@redhat.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "http://support.apple.com/kb/HT4077",
"source": "user@redhat.com",
"tags": null
},
{
"url": "http://www.debian.org/security/2010/dsa-2001",
"source": "user@redhat.com",
"tags": null
},
{
"url": "http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995",
"source": "user@redhat.com",
"tags": null
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": null,
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"access_vector": "NETWORK",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "COMPLETE",
"integrity_impact": "COMPLETE",
"availability_impact": "COMPLETE",
"base_score": 10.0,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "HIGH",
"exploitability_score": 10.0,
"impact_score": 10.0,
"ac_insuf_info": false,
"obtain_all_privilege": false,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"match_criteria_id": "DD613CC3-281B-43D1-A352-53D339B040FA",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "5.2.11",
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:*",
"match_criteria_id": "92647629-083F-4042-8365-4AD2EBC9C1BF",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:*",
"match_criteria_id": "FF72E8D5-9F8C-4BD4-9AA4-28E23CB48A47",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:*",
"match_criteria_id": "83BE1120-6370-4470-8586-6581EDF3FD69",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*",
"match_criteria_id": "245C601D-0FE7-47E3-8304-6FF45E9567D6",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0.1:*:*:*:*:*:*:*",
"match_criteria_id": "691BB8BB-329A-4640-B758-7590C99B5E42",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0.2:*:*:*:*:*:*:*",
"match_criteria_id": "E2BC4CCE-2774-463E-82EA-36CD442D3A7B",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0.3:*:*:*:*:*:*:*",
"match_criteria_id": "C478024C-2FCD-463F-A75E-E04660AA9DF1",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0.4:*:*:*:*:*:*:*",
"match_criteria_id": "AC9C32F4-5102-4E9B-9F32-B24B65A5ED2F",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:php:php:3.0.5:*:*:*:*:*:*:*",
"match_criteria_id": "A5BD99C0-E875-496E-BE5E-A8DCBD414B5C",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": [
{
"organization": "Red Hat",
"comment": "We do not consider safe_mode / open_basedir restriction bypass issues being security sensitive. For more details see http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=169857#c1 and http://www.php.net/security-note.php",
"last_modified": "2009-12-23T00:00:00Z"
}
],
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:a:php:php:*:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "5.2.11",
"version_end_excluding": null,
"affected_versions_first": "0.1",
"affected_versions_last": "5.2.11"
},
{
"criteria": "cpe:2.3:a:php:php:1.0:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "1.0",
"affected_versions_last": "1.0"
},
{
"criteria": "cpe:2.3:a:php:php:2.0:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0",
"affected_versions_last": "2.0"
},
{
"criteria": "cpe:2.3:a:php:php:2.0b10:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "2.0b10",
"affected_versions_last": "2.0b10"
},
{
"criteria": "cpe:2.3:a:php:php:3.0:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0",
"affected_versions_last": "3.0"
},
{
"criteria": "cpe:2.3:a:php:php:3.0.1:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0.1",
"affected_versions_last": "3.0.1"
},
{
"criteria": "cpe:2.3:a:php:php:3.0.2:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0.2",
"affected_versions_last": "3.0.2"
},
{
"criteria": "cpe:2.3:a:php:php:3.0.3:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0.3",
"affected_versions_last": "3.0.3"
},
{
"criteria": "cpe:2.3:a:php:php:3.0.4:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0.4",
"affected_versions_last": "3.0.4"
},
{
"criteria": "cpe:2.3:a:php:php:3.0.5:*:*:*:*:*:*:*",
"vendor": "php",
"product": "php",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "3.0.5",
"affected_versions_last": "3.0.5"
}
],
"cwe": null,
"epss_score": {
"epss": 0.02946,
"percentile": 0.86567,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": null,
"user_interaction": null,
"vulnerable_system_confidentiality": "COMPLETE",
"vulnerable_system_integrity": "COMPLETE",
"vulnerable_system_availability": "COMPLETE",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 10.0,
"base_severity": "HIGH"
}
}
}
},
{
"id": "CVE-2009-3245",
"source_identifier": "user@mitre.org",
"published": "2010-03-05T19:30:00Z",
"last_modified": "2026-06-16T23:11:13Z",
"status": "Modified",
"evaluator_comment": null,
"evaluator_solution": null,
"evaluator_impact": null,
"cisa_exploit_add": null,
"cisa_action_due": null,
"cisa_required_action": null,
"cisa_vulnerability_name": null,
"descriptions": [
{
"lang": "en",
"value": "OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors."
},
{
"lang": "es",
"value": "OpenSSL en versiones anterioes a v0.9.8m cuando recibe un valor de retorno NULL de la funcion bn_wexpand hace una llamada a (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, y (4) engines/e_ubsec.c, lo que tiene un impacto inespecifico y vectores de ataque dependientes del contexto."
}
],
"references": [
{
"url": "http://aix.software.ibm.com/aix/efixes/security/openssl_advisory.asc",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://lists.apple.com/archives/security-announce/2011//Jun/msg00000.html",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/038587.html",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://marc.info/?l=bugtraq&m=127128920008563&w=2",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://marc.info/?l=bugtraq&m=127678688104458&w=2",
"source": "user@mitre.org",
"tags": null
},
{
"url": "http://marc.info/?l=openssl-cvs&m=126692159706582&w=2",
"source": "user@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://marc.info/?l=openssl-cvs&m=126692170906712&w=2",
"source": "user@mitre.org",
"tags": [
"Patch"
]
},
{
"url": "http://marc.info/?l=openssl-cvs&m=126692180606861&w=2",
"source": "user@mitre.org",
"tags": [
"Patch"
]
}
],
"metrics": {
"cvss_metric_v40": null,
"cvss_metric_v31": null,
"cvss_metric_v30": null,
"cvss_metric_v2": [
{
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"access_vector": "NETWORK",
"access_complexity": "LOW",
"authentication": "NONE",
"confidentiality_impact": "COMPLETE",
"integrity_impact": "COMPLETE",
"availability_impact": "COMPLETE",
"base_score": 10.0,
"exploitability": null,
"remediation_level": null,
"report_confidence": null,
"temporal_score": null,
"collateral_damage_potential": null,
"target_distribution": null,
"confidentiality_requirement": null,
"integrity_requirement": null,
"availability_requirement": null,
"environmental_score": null
},
"base_severity": "HIGH",
"exploitability_score": 10.0,
"impact_score": 10.0,
"ac_insuf_info": true,
"obtain_all_privilege": false,
"obtain_user_privilege": false,
"obtain_other_privilege": false,
"user_interaction_required": false
}
]
},
"weaknesses": [
{
"source": "user@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"operator": null,
"negate": null,
"nodes": [
{
"operator": "OR",
"negate": false,
"cpe_match": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
"match_criteria_id": "81FB3B26-CC83-4FA5-BDE1-05F35AB99741",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "0.9.8l",
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*",
"match_criteria_id": "8A4E446D-B9D3-45F2-9722-B41FA14A6C31",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*",
"match_criteria_id": "AF4EA988-FC80-4170-8933-7C6663731981",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*",
"match_criteria_id": "64F8F53B-24A1-4877-B16E-F1917C4E4E81",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*",
"match_criteria_id": "75D3ACD5-905F-42BB-BE1A-8382E9D823BF",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:*",
"match_criteria_id": "766EA6F2-7FA4-4713-9859-9971CCD2FDCB",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:*",
"match_criteria_id": "EFBC30B7-627D-48DC-8EF0-AE8FA0C6EDBA",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*",
"match_criteria_id": "2BB38AEA-BAF0-4920-9A71-747C24444770",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*",
"match_criteria_id": "1F33EA2B-DE15-4695-A383-7A337AC38908",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*",
"match_criteria_id": "261EE631-AB43-44FE-B02A-DFAAB8D35927",
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null
}
]
}
]
}
],
"vendor_comments": [
{
"organization": "Red Hat",
"comment": "Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2009-3245\n\nThis issue was fixed in openssl packages in Red Hat Enterprise Linux 5 via: https://rhn.redhat.com/errata/RHSA-2010-0162.html\n\nThis issue was fixed in openssl096b packages in Red Hat Enterprise Linux 3 and 4 via: https://rhn.redhat.com/errata/RHSA-2010-0173.html\n\nThe Red Hat Security Response Team has rated this issue as having low security impact on openssl packages in Red Hat Enterprise Linux 3 and 4, a future update may address this flaw.",
"last_modified": "2010-03-25T00:00:00Z"
}
],
"enrichment": {
"cpe": [
{
"criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": "0.9.8l",
"version_end_excluding": null,
"affected_versions_first": "0.9.6d",
"affected_versions_last": "0.9.8"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8",
"affected_versions_last": "0.9.8"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8a:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8a",
"affected_versions_last": "0.9.8a"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8b:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8b",
"affected_versions_last": "0.9.8b"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8c:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8c",
"affected_versions_last": "0.9.8c"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8d:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8d",
"affected_versions_last": "0.9.8d"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8e:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8e",
"affected_versions_last": "0.9.8e"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8f",
"affected_versions_last": "0.9.8f"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8g",
"affected_versions_last": "0.9.8g"
},
{
"criteria": "cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*",
"vendor": "openssl",
"product": "openssl",
"product_type": "a",
"vulnerable": true,
"version_start_including": null,
"version_start_excluding": null,
"version_end_including": null,
"version_end_excluding": null,
"affected_versions_first": "0.9.8h",
"affected_versions_last": "0.9.8h"
}
],
"cwe": [
{
"id": 20,
"owasptop10_2021": "A03 Injection",
"name": "Improper Input Validation",
"description": "The product receives input or data, but it does\n not validate or incorrectly validates that the input has the\n properties that are required to process the data safely and\n correctly.",
"capec_id": [
3,
7,
8,
9,
10,
13,
14,
22,
23,
24
],
"scope": [
"Availability",
"Confidentiality",
"Integrity"
],
"impact": [
"DoS: Crash, Exit, or Restart",
"DoS: Resource Consumption (CPU)",
"DoS: Resource Consumption (Memory)",
"Execute Unauthorized Code or Commands",
"Modify Memory",
"Read Files or Directories",
"Read Memory"
],
"detection_method": [
"Architecture or Design Review",
"Automated Static Analysis",
"Automated Static Analysis - Binary or Bytecode",
"Automated Static Analysis - Source Code",
"Dynamic Analysis with Automated Results Interpretation",
"Dynamic Analysis with Manual Results Interpretation",
"Fuzzing",
"Manual Static Analysis",
"Manual Static Analysis - Binary or Bytecode",
"Manual Static Analysis - Source Code"
]
}
],
"epss_score": {
"epss": 0.06471,
"percentile": 0.93442,
"date": "2026-09-23"
},
"cisa_kev": null,
"vdeep_metric": {
"available_versions": [
"2.0"
],
"source": "user@nist.gov",
"type": "Primary",
"cvss_data": {
"version": "2.0",
"vector_string": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"attack_vector": "NETWORK",
"attack_complexity": "LOW",
"attack_requirements": null,
"privileges_required": null,
"user_interaction": null,
"vulnerable_system_confidentiality": "COMPLETE",
"vulnerable_system_integrity": "COMPLETE",
"vulnerable_system_availability": "COMPLETE",
"subsequent_system_confidentiality": null,
"subsequent_system_integrity": null,
"subsequent_system_availability": null,
"exploit_maturity": null,
"confidentiality_requirements": null,
"integrity_requirements": null,
"availability_requirements": null,
"modified_attack_vector": null,
"modified_attack_complexity": null,
"modified_attack_requirements": null,
"modified_privileges_required": null,
"modified_user_interaction": null,
"modified_vulnerable_system_confidentiality": null,
"modified_vulnerable_system_integrity": null,
"modified_vulnerable_system_availability": null,
"modified_subsequent_system_confidentiality": null,
"modified_subsequent_system_integrity": null,
"modified_subsequent_system_availability": null,
"safety": null,
"automatable": null,
"recovery": null,
"value_density": null,
"vulnerability_response_effort": null,
"provider_urgency": null,
"base_score": 10.0,
"base_severity": "HIGH"
}
}
}
}
]
}