Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2011-0014

23
FAUCET Score

CVE-2011-0014 is a denial-of-service vulnerability affecting OpenSSL versions 0.9.8h through 0.9.8q and 1.0.0 through 1.0.0c. A remote attacker can trigger an out-of-bounds memory access and crash applications using OpenSSL by sending a malformed ClientHello handshake message, also known as the "OCSP stapling vulnerability." This vulnerability has a CVSS score of 5.0, indicating a low severity with network access and no authentication required, potentially leading to a partial denial of service. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
0.9.8hCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.8h:*:*:*:*:*:*:*
0.9.8iCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.8i:*:*:*:*:*:*:*
0.9.8jCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.8j:*:*:*:*:*:*:*
0.9.8kCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.8k:*:*:*:*:*:*:*
0.9.8lCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:0.9.8l:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
9.85%
Probability of exploitation in next 30 days
EPSS Percentile
95.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0985 is in the 94th percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl-0:1.0.0-10.el6
View patch

Vendor Advisories (1)

redhatCVE-2011-0014Moderate

openssl: OCSP stapling vulnerability

Feb 8, 2011

References

ftp.netbsd.org / pub/NetBSD/security/advisories/NetBSD-SA2011-002.txt.asc
h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
lists.apple.com / archives/security-announce/2011//Jun/msg00000.html
lists.fedoraproject.org / pipermail/package-announce/2011-February/054007.html
lists.opensuse.org / opensuse-security-announce/2011-04/msg00000.html
marc.info
marc.info
osvdb.org / 70847
secunia.com / advisories/43227
Vendor Advisory
secunia.com / advisories/43286
Vendor Advisory
secunia.com / advisories/43301
Vendor Advisory
secunia.com / advisories/43339
Vendor Advisory
secunia.com / advisories/44269
secunia.com / advisories/57353
slackware.com / security/viewer.php
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A18985
support.f5.com / csp/article/K10534046
support.apple.com / kb/HT4723
www-01.ibm.com / support/docview.wss
debian.org / security/2011/dsa-2162
mandriva.com / security/advisories
openssl.org / news/secadv_20110208.txt
PatchVendor Advisory
redhat.com / support/errata/RHSA-2011-0677.html
securityfocus.com / bid/46264
securitytracker.com / id
ubuntu.com / usn/USN-1064-1
vupen.com / english/advisories/2011/0361
Vendor Advisory
vupen.com / english/advisories/2011/0387
Vendor Advisory
vupen.com / english/advisories/2011/0389
Vendor Advisory
vupen.com / english/advisories/2011/0395
Vendor Advisory
vupen.com / english/advisories/2011/0399
Vendor Advisory
vupen.com / english/advisories/2011/0603