CVE-2011-0014 is a denial-of-service vulnerability affecting OpenSSL versions 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c. A remote attacker can trigger an out-of-bounds memory access and crash applications using OpenSSL by sending a malformed ClientHello handshake message, also known as the "OCSP stapling vulnerability." This vulnerability has a CVSS score of 5.0, indicating a low severity with network access and no authentication required, potentially leading to a partial denial of service. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.9.8hCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:* | ||
0.9.8iCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:* | ||
0.9.8jCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:* | ||
0.9.8kCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8k:*:*:*:*:*:*:* | ||
0.9.8lCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.8l:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.