peter bassill · operator
$ cve CVE-2016-2108 JSON

CVE-2016-2108

9.8
CRITICAL · CVSS 3.0 · EPSS 77.9% (pctl 100)

Patch early

EPSS 77.9% — above the 10% action threshold.

Description

The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS77.91% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploitnone known
Published2016-05-05
Last modified2026-06-17

Affected (9)

VendorProduct
googleandroid
opensslopenssl
redhatenterprise linux desktop
redhatenterprise linux hpc node
redhatenterprise linux hpc node eus
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux workstation

References

→ the Explorer  ·  watch your stack  ·  NVD