CVE-2015-3196 is a denial-of-service vulnerability affecting OpenSSL versions 1.0.0, 1.0.1, and 1.0.2, specifically impacting multi-threaded clients. A remote server can trigger a race condition and double free by sending a crafted ServerKeyExchange message, leading to a denial of service. The vulnerability has a CVSS score of 4.3, indicating medium attack complexity and a partial availability impact, with no confidentiality or integrity impact. There is no evidence of active exploitation, and no public exploit code or Metasploit modules are available. Community discussion and media coverage are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:a:hp:icewall_sso:10.0:*:*:*:certd:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:hp:icewall_sso_agent_option:10.0:*:*:*:*:*:*:* | ||
1.0.0CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:* | ||
1.0.0aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:* | ||
1.0.0bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.