CVE-2004-0079 describes a denial-of-service vulnerability in OpenSSL versions 0.9.6c through 0.9.6k and 0.9.7a through 0.9.7c, affecting numerous products including those from Apple, Cisco, and Red Hat. This high-severity flaw (CVSS 7.5) allows remote unauthenticated attackers to crash affected systems via a crafted SSL/TLS handshake that triggers a null dereference. While there is no evidence of active exploitation, no public exploit code, and it is not listed in CISA's KEV catalog, the vulnerability has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:h:cisco:firewall_services_module:*:*:*:*:*:*:*:* | ||
1.1.2CPE matchmatch criteria | cpe:2.3:h:cisco:firewall_services_module:1.1.2:*:*:*:*:*:*:* | ||
1.1.3CPE matchmatch criteria | cpe:2.3:h:cisco:firewall_services_module:1.1.3:*:*:*:*:*:*:* | ||
1.1_\(3.005\)CPE matchmatch criteria | cpe:2.3:h:cisco:firewall_services_module:1.1_\(3.005\):*:*:*:*:*:*:* | ||
2.1_\(0.208\)CPE matchmatch criteria | cpe:2.3:h:cisco:firewall_services_module:2.1_\(0.208\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.