FreeBSD VuXML

Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Security issues that affect the FreeBSD operating system or applications in the FreeBSD Ports Collection are documented using the Vulnerabilities and Exposures Markup Language (VuXML). The current VuXML document that serves as the source for the content of this site can be found:

Please report security issues to the FreeBSD Security Team at . Full contact details, including information handling policies and PGP key, can be found on the FreeBSD Security page.

openssl


Entered Topic
2024-10-19 OpenSSL -- OOB memory access vulnerability
2024-09-03 OpenSSL -- Multiple vulnerabilities
2024-05-28 OpenSSL -- Use after free vulnerability
2024-05-17 OpenSSL -- Denial of Service vulnerability
2024-04-11 OpenSSL -- Unbounded memory growth with session handling in TLSv1.3
2024-01-31 OpenSSL -- Multiple vulnerabilities
2024-01-11 OpenSSL -- Vector register corruption on PowerPC
2023-11-08 OpenSSL -- DoS in DH generation
2023-10-24 OpenSSL -- potential loss of confidentiality
2023-07-31 OpenSSL -- Excessive time spent checking DH q parameter value
2023-05-31 OpenSSL -- Possible DoS translating ASN.1 identifiers
2023-03-29 OpenSSL -- Multiple vulnerabilities
2023-03-24 OpenSSL -- Excessive Resource Usage Verifying X.509 Policy Constraints
2023-02-07 OpenSSL -- Multiple vulnerabilities
2022-07-05 OpenSSL -- AES OCB fails to encrypt some bytes
2022-06-22 OpenSSL -- Command injection vulnerability
2022-05-04 OpenSSL -- Multiple vulnerabilities
2022-03-16 OpenSSL -- Infinite loop in BN_mod_sqrt parsing certificates
2022-01-28 OpenSSL -- BN_mod_exp incorrect results on MIPS
2021-08-24 OpenSSL -- multiple vulnerabilities
2021-03-26 OpenSSL -- Multiple vulnerabilities
2021-02-16 OpenSSL -- Multiple vulnerabilities
2020-12-08 OpenSSL -- NULL pointer de-reference
2020-04-21 OpenSSL remote denial of service vulnerability
2019-12-20 OpenSSL -- Overflow vulnerability
2019-09-11 OpenSSL -- Multiple vulnerabilities
2019-02-20 OpenSSL -- Padding oracle vulnerability
2018-11-12 OpenSSL -- timing vulnerability
2018-06-12 OpenSSL -- Client DoS due to large DH parameter
2018-04-16 OpenSSL -- Cache timing vulnerability
2018-03-27 OpenSSL -- multiple vulnerabilities
2017-12-07 OpenSSL -- multiple vulnerabilities
2017-11-02 OpenSSL -- Multiple vulnerabilities
2017-01-26 OpenSSL -- multiple vulnerabilities
2017-01-11 openssl -- timing attack vulnerability
2016-11-02 FreeBSD -- OpenSSL Remote DoS vulnerability
2016-09-26 OpenSSL -- multiple vulnerabilities
2016-09-22 OpenSSL -- multiple vulnerabilities
2016-06-30 openssl -- denial of service
2016-06-09 OpenSSL -- vulnerability in DSA signing
2016-05-03 OpenSSL -- multiple vulnerabilities
2016-01-28 openssl -- multiple vulnerabilities
2015-12-05 openssl -- multiple vulnerabilities
2015-07-09 openssl -- alternate chains certificate forgery vulnerability
2015-06-11 openssl -- multiple vulnerabilities
2015-03-19 OpenSSL -- multiple vulnerabilities
2015-01-08 OpenSSL -- multiple vulnerabilities
2014-10-15 OpenSSL -- multiple vulnerabilities
2014-08-06 OpenSSL -- multiple vulnerabilities
2014-06-05 OpenSSL -- multiple vulnerabilities
2014-05-03 OpenSSL -- NULL pointer dereference / DoS
2014-04-23 OpenSSL -- Remote Data Injection / DoS
2014-04-11 OpenSSL -- Local Information Disclosure
2014-04-07 OpenSSL -- Remote Information Disclosure
2014-01-06 openssl -- multiple vulnerabilities
2013-02-06 OpenSSL -- TLS 1.1, 1.2 denial of service
2012-05-10 OpenSSL -- DTLS and TLS 1.1, 1.2 denial of service
2012-04-21 OpenSSL -- integer conversions result in memory corruption
2012-03-15 OpenSSL -- CMS and S/MIME Bleichenbacher attack
2012-01-20 OpenSSL -- DTLS Denial of Service
2012-01-14 OpenSSL -- multiple vulnerabilities
2011-09-07 OpenSSL -- multiple vulnerabilities
2010-11-17 openssl -- TLS extension parsing race condition
2009-05-30 openssl -- denial of service in DTLS implementation
2007-02-26 OpenSSL -- Multiple problems in crypto(3)
2006-12-19 openssl -- Incorrect PKCS#1 v1.5 padding validation in crypto(3)
2005-10-12 openssl -- potential SSL 2.0 rollback
2004-03-17 OpenSSL ChangeCipherSpec denial-of-service vulnerability