CVE-2016-0705 is a critical double free vulnerability in the dsa_priv_decode function of OpenSSL versions 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g, affecting products from vendors like Canonical, Debian, Google, and Oracle. With a CVSS score of 9.8 (CRITICAL), this vulnerability allows remote attackers to cause a denial of service through memory corruption or potentially achieve other unspecified impacts via a malformed DSA private key, requiring no user interaction or complex attack conditions. Despite its high severity and significant media coverage (1 article, top 5% of CVEs), there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog, suggesting it is not actively exploited in the wild. Community discussion is minimal, with only one mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.6.0, <= 5.6.29CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
>= 5.7.0, <= 5.7.11CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.