CVE-2007-4995

Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 13 Oct 2007, 01:00
Last modified:07 Aug 2024, 15:17

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 HIGH
v2.0 (nvd)
EPSS Score
12.51% MEDIUM
13% probability +2.16%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Oct 2007, 01:00
Published
Vulnerability first disclosed
07 Aug 2024, 15:17
Last Modified
Vulnerability information updated

Description

Off-by-one error in the DTLS implementation in OpenSSL 0.9.8 before 0.9.8f allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS Metrics

  • v2.0HIGHScore: 9.3AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 12.51% Percentile: 94%

Techniques & Countermeasures

  • CWE-189Numeric Errors

    Weaknesses in this category are related to improper calculation or conversion of numbers.

Affected Systems

  • UnknownOpenSSL

    0.9.8 | 0.9.8a | 0.9.8b | 0.9.8c | 0.9.8d | 0.9.8e

References (31)