CyberSec.Space Logo
Back to CVE Browser

CVE-2009-3245

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1760%
EPSS Percentile19.65th
PublishedMar 5, 2010
Last ModifiedApr 29, 2026

Vulnerability Description

OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.

Affected Platforms (CPE)

πŸ“¦
Openssl

Openssl

<= 0.9.8l
πŸ“¦
Openssl

Openssl

= 0.9.8
πŸ“¦
Openssl

Openssl

= 0.9.8a
πŸ“¦
Openssl

Openssl

= 0.9.8b
πŸ“¦
Openssl

Openssl

= 0.9.8c
πŸ“¦
Openssl

Openssl

= 0.9.8d
πŸ“¦
Openssl

Openssl

= 0.9.8e
πŸ“¦
Openssl

Openssl

= 0.9.8f
πŸ“¦
Openssl

Openssl

= 0.9.8g
πŸ“¦
Openssl

Openssl

= 0.9.8h
πŸ“¦
Openssl

Openssl

= 0.9.8i
πŸ“¦
Openssl

Openssl

= 0.9.8j
πŸ“¦
Openssl

Openssl

= 0.9.8k

References & Advisories

Related Vulnerabilities