Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-0798

37
FAUCET Score

CVE-2016-0798 is a memory leak vulnerability in OpenSSL versions 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g, specifically within the SRP_VBASE_get_by_user implementation. A remote attacker can trigger this by providing an invalid username during a connection attempt, leading to a denial of service through memory consumption. Rated with a CVSS score of 7.5 (HIGH), this vulnerability is network-exploitable with low attack complexity and can result in high availability impact. While it garnered significant media coverage and community discussion at the time, there is no evidence of active exploitation, nor are there publicly available exploits in common frameworks like Metasploit or ExploitDB.

Impacted Technologies

VendorProductVersion(s)CPE
1.0.1CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.1:*:*:*:*:*:*:*
1.0.1CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.1:beta1:*:*:*:*:*:*
1.0.1CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.1:beta2:*:*:*:*:*:*
1.0.1CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.1:beta3:*:*:*:*:*:*
1.0.1aCPE matchmatch criteria
cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
24.41%
Probability of exploitation in next 30 days
EPSS Percentile
97.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.2441 is in the 96th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2016-0798Low

OpenSSL: Avoid memory leak in SRP

Feb 25, 2016

References

kb.juniper.net / InfoCenter/index
lists.opensuse.org / opensuse-security-announce/2016-03/msg00001.html
lists.opensuse.org / opensuse-security-announce/2016-03/msg00002.html
lists.opensuse.org / opensuse-security-announce/2016-03/msg00003.html
lists.opensuse.org / opensuse-security-announce/2016-03/msg00005.html
lists.opensuse.org / opensuse-security-announce/2016-03/msg00006.html
lists.opensuse.org / opensuse-security-announce/2016-03/msg00009.html
lists.opensuse.org / opensuse-security-announce/2016-03/msg00010.html
openssl.org / news/secadv/20160301.txt
Vendor Advisory
cert-portal.siemens.com / productcert/pdf/ssa-412672.pdf
git.openssl.org
h20566.www2.hpe.com / hpsc/doc/public/display
kb.pulsesecure.net / articles/Pulse_Security_Advisories/SA40168
security.freebsd.org / advisories/FreeBSD-SA-16:12.openssl.asc
security.gentoo.org / glsa/201603-15
openssl.org / news/secadv/20160301.txt
tools.cisco.com / security/center/content/CiscoSecurityAdvisory/cisco-sa-20160302-openssl
debian.org / security/2016/dsa-3500
oracle.com / technetwork/security-advisory/cpuapr2016v3-2985753.html
oracle.com / technetwork/security-advisory/cpujul2016-2881720.html
oracle.com / technetwork/topics/security/bulletinapr2016-2952098.html
securityfocus.com / bid/83705
securityfocus.com / bid/91787
securitytracker.com / id/1035133
ubuntu.com / usn/USN-2914-1