← All CVEs

CVE-2016-7052

high · 7.5

crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.

7.5
CVSS
30.2%
EPSS (exploit prob.)
98th
EPSS percentile
2016-09-26
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Weaknesses

CWE-476

Affected products

VendorProductAffected versions
novellsuse_linux_enterprise_module_for_web_scripting12.0
opensslopenssl1.0.2i
nodejsnode.js>= 4.0.0, <= 4.1.2
nodejsnode.js>= 4.2.0, < 4.6.0
nodejsnode.js>= 6.0.0, < 6.7.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2016-7052