QSearchQSearch

CVE-2014-3566

3.4 LOW

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for ...

Published: 2014-10-15 · Last updated: 2026-05-28

Severity and scoring

CVSS
3.4 LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N
CWE
CWE-310, CWE-329

Affected products

VendorProduct
appleaix, database, debian_linux
debianaix, database, debian_linux
fedoraprojectaix, database, debian_linux
ibmaix, database, debian_linux
mageiaaix, database, debian_linux
netbsdaix, database, debian_linux
novellaix, database, debian_linux
opensslaix, database, debian_linux
opensuseaix, database, debian_linux
oracleaix, database, debian_linux
redhataix, database, debian_linux

Description

The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-49975 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP ... (7.5 HIGH)
  • CVE-2026-50259 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland (7.8 HIGH)
  • CVE-2026-50258 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland (7.8 HIGH)
  • CVE-2026-50257 A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence() (7.8 HIGH)
  • CVE-2026-50256 A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland (7.8 HIGH)

Same CWE

  • CVE-2026-45787 electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client (9.1 CRITICAL)
  • CVE-2026-49000 An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management... (7.0 HIGH)
  • CVE-2017-14852 An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SS... (8.6 HIGH)
  • CVE-2019-6576 A vulnerability has been identified in SIMATIC HMI Comfort Panels 4" - 22" (All versions < V15.1 Update 1), SIMATIC HMI Comfort Outdoor P... (6.5 MEDIUM)
  • CVE-2015-4000 The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DH... (3.7 LOW)