← back
CVE-2006-4343

CVE-2006-4343

28Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 17%
from disclosure to weapon0 days
Published on NVDSep 28
1st PoCSep 28
exploitation probability
17%top 3% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions allows remote servers to cause a denial of service (client crash) via unknown vectors that trigger a null pointer dereference.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.