Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-0206

42
FAUCET Score

CVE-2015-0206 is a memory leak vulnerability in the dtls1_buffer_record function of OpenSSL versions 1.0.0 before 1.0.0p and 1.0.1 before 1.0.1k. This flaw allows remote attackers to cause a denial of service by sending numerous duplicate records, leading to excessive memory consumption. With a CVSS score of 5.0, it is a low-severity vulnerability that requires no authentication and has a low attack complexity, primarily impacting availability. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it garnered some community discussion and media coverage at the time of disclosure.

Impacted Technologies

VendorProductVersion(s)CPE
1.0.0aCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*
1.0.0bCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*
1.0.0cCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*
1.0.0dCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*
1.0.0eCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
59.32%
Probability of exploitation in next 30 days
EPSS Percentile
99.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.5932 is in the 99th percentile among its peer group of 23,725 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: openssl-0:1.0.1e-30.el6_6.5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: openssl-1:1.0.1e-34.el7_0.7
View patch
redhatno patchvia redhat_api
Product: Red Hat Storage 2.1Fixed in: openssl

Vendor Advisories (1)

redhatCVE-2015-0206Moderate

openssl: DTLS memory leak in dtls1_buffer_record

Jan 8, 2015

References

lists.fedoraproject.org / pipermail/package-announce/2015-January/147938.html
lists.fedoraproject.org / pipermail/package-announce/2015-January/148363.html
lists.opensuse.org / opensuse-security-announce/2015-01/msg00021.html
lists.opensuse.org / opensuse-security-announce/2015-05/msg00026.html
lists.opensuse.org / opensuse-security-announce/2015-07/msg00037.html
marc.info
marc.info
marc.info
marc.info
marc.info
marc.info
rhn.redhat.com / errata/RHSA-2015-0066.html
bto.bluecoat.com / security-advisory/sa88
exchange.xforce.ibmcloud.com / vulnerabilities/99704
github.com / openssl/openssl/commit/103b171d8fc282ef435f8de9afbf7782e312961f
kc.mcafee.com / corporate/index
kc.mcafee.com / corporate/index
openssl.org / news/secadv_20150108.txt
Vendor Advisory
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20150310-ssl
debian.org / security/2015/dsa-3125
mandriva.com / security/advisories
mandriva.com / security/advisories
oracle.com / technetwork/security-advisory/cpujul2016-2881720.html
oracle.com / technetwork/security-advisory/cpuoct2017-3236626.html
oracle.com / technetwork/topics/security/bulletinjan2015-2370101.html
oracle.com / technetwork/topics/security/cpuapr2015-2365600.html
oracle.com / technetwork/topics/security/cpujul2015-2367936.html
oracle.com / technetwork/topics/security/cpuoct2015-2367953.html
securityfocus.com / bid/71940
securityfocus.com / bid/91787
securitytracker.com / id/1033378