Sploitus

CVE-2016-2106

1 known exploit for CVE-2016-2106

Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data.

Openssl
≤ 1.0.1s, 1.0.2, 1.0.2a, 1.0.2b, 1.0.2c, 1.0.2d, 1.0.2e, 1.0.2f, 1.0.2g
Fix
Available
CVSS 3.0
7.5 HIGH
EPSS
27.3% (98th percentile)
Weakness
CWE-189
NVD status
Modified
Published
2016-05-05
CVE-2016-2106 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2016-2106

Proof-of-concept code and exploit modules indexed by Sploitus