Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2010-3864

36
FAUCET Score

CVE-2010-3864 describes multiple race conditions in OpenSSL versions 0.9.8f through 0.9.8o, 1.0.0, and 1.0.0a, specifically within the ssl/t1_lib.c file. These vulnerabilities, triggered when multi-threading and internal caching are enabled on a TLS server, could lead to a heap-based buffer overflow via client data related to TLS server name extensions or elliptic curve cryptography. With a CVSS score of 7.6, this vulnerability is considered highly severe due to its network-based attack vector, high attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
0.9.8fCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.8f:*:*:*:*:*:*:*
0.9.8gCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.8g:*:*:*:*:*:*:*
0.9.8hCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*
0.9.8iCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:*
0.9.8jCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.6HIGH

AV:N/AC:H/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
22.14%
Probability of exploitation in next 30 days
EPSS Percentile
97.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.2215 is in the 88th percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

opensslpatch availablevia llm_extracted
Fixed in: 4.1.6
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl-0:1.0.0-4.el6_0.1
View patch

Vendor Advisories (2)

opensslllm-openssl-744ed5e6f58fb0f0

Splunk 4.1.6 updates OpenSSL to 0.9.8p address CVE-2010-3864

Dec 1, 2010
redhatCVE-2010-3864Important

OpenSSL TLS extension parsing race condition

Nov 16, 2010

References

blogs.sun.com / security/entry/cve_2010_3864_race_condition
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
lists.apple.com / archives/security-announce/2011//Jun/msg00000.html
lists.fedoraproject.org / pipermail/package-announce/2010-November/051170.html
lists.fedoraproject.org / pipermail/package-announce/2010-November/051237.html
lists.fedoraproject.org / pipermail/package-announce/2010-November/051255.html
lists.opensuse.org / opensuse-security-announce/2010-11/msg00006.html
marc.info
marc.info
marc.info
openssl.org / news/secadv_20101116.txt
PatchVendor Advisory
bugzilla.redhat.com / show_bug.cgi
Patch
secunia.com / advisories/42241
secunia.com / advisories/42243
Vendor Advisory
secunia.com / advisories/42309
secunia.com / advisories/42336
secunia.com / advisories/42352
secunia.com / advisories/42397
secunia.com / advisories/42413
secunia.com / advisories/43312
secunia.com / advisories/44269
secunia.com / advisories/57353
security.freebsd.org / advisories/FreeBSD-SA-10:10.openssl.asc
securitytracker.com / id
Patch
slackware.com / security/viewer.php
lists.balabit.com / pipermail/syslog-ng-announce/2011-January/000101.html
lists.balabit.com / pipermail/syslog-ng-announce/2011-January/000102.html
rhn.redhat.com / errata/RHSA-2010-0888.html
support.apple.com / kb/HT4723
www-01.ibm.com / support/docview.wss
adobe.com / support/security/bulletins/apsb11-11.html
debian.org / security/2010/dsa-2125
kb.cert.org / vuls/id/737740
US Government Resource
securityfocus.com / archive/1/516397/100/0/threaded
vmware.com / security/advisories/VMSA-2011-0003.html
vupen.com / english/advisories/2010/3041
vupen.com / english/advisories/2010/3077
vupen.com / english/advisories/2010/3097
vupen.com / english/advisories/2010/3121