CVE-2016-2105
—CVSS 3.1
7.5 high
EPSS
40%p99
Published
()
Modified
Description
Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data.
- Vendors
- redhatopensuseoracleappleopenssldebiancanonicalnodejs
- Products
- enterprise linux desktop, enterprise linux hpc node, enterprise linux server, enterprise linux workstation, leap, opensuse, mysql, enterprise linux hpc node eus, enterprise linux server aus, enterprise linux server eus, mac os x, openssl
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.