← All CVEs

CVE-2008-0166

high · 7.5

OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.

7.5
CVSS
70.7%
EPSS (exploit prob.)
99th
EPSS percentile
2008-05-13
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses

CWE-338

Affected products

VendorProductAffected versions
opensslopenssl>= 0.9.8c-1, <= 0.9.8g
canonicalubuntu_linux6.06
canonicalubuntu_linux7.04
canonicalubuntu_linux7.10
canonicalubuntu_linux8.04
debiandebian_linux4.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-0166