Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2011-1945

EPSS 4.85% · P90
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2011-1945

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
The elliptic curve cryptography (ECC) subsystem in OpenSSL 1.0.0d and earlier, when the Elliptic Curve Digital Signature Algorithm (ECDSA) is used for the ECDHE_ECDSA cipher suite, does not properly implement curves over binary fields, which makes it easier for context-dependent attackers to determine private keys via a timing attack and a lattice calculation.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
OpenSSL ECC子系统加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenSSL是OpenSSL团队开发的一个开源的能够实现安全套接层(SSL v2/v3)和安全传输层(TLS v1)协议的通用加密库,它支持多种加密算法,包括对称密码、哈希算法、安全散列算法等。 当ECDHE_ECDSA密码套件使用Elliptic Curve Digital Signature Algorithm(ECDSA)算法时,OpenSSL 1.0.0d及之前版本中的elliptic curve cryptography(ECC)子系统没有正确实现用二进制字段表示的曲线。攻击者可以借助定时攻击
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2011-1945

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2011-1945

登录查看更多情报信息。

Same Patch Batch · n/a · 2011-05-31 · 28 CVEs total

CVE-2011-1486Red Hat libvirt libvirtd拒绝服务漏洞
CVE-2011-2215Walrus_Digit WalRack未明漏洞
CVE-2011-22147T Interactive Graphical SCADA System ODBC远程内存破坏漏洞
CVE-2011-1938PHP ext/sockets/sockets.c socket_connect函数栈缓冲区溢出漏洞
CVE-2011-1937Webmin跨站脚本攻击漏洞
CVE-2011-1925Wouter_Verhelst Network Block Device拒绝服务漏洞
CVE-2011-1922Nlnetlabs Unbound DNS解析器远程拒绝服务漏洞
CVE-2011-1910ISC BIND 9 Negative Caching RRSIG RRsets off-by-one错误漏洞
CVE-2011-1651Cisco IOS XR SPA接口处理器远程拒绝服务漏洞
CVE-2011-1649Cisco Content Delivery System Internet Streamer URL处理远程拒绝服务漏洞
CVE-2011-1647Cisco RVS4000和WRVS4400N Web管理界面信息泄露漏洞
CVE-2011-1646Cisco RVS4000和WRVS4400N Web管理界面远程命令注入漏洞
CVE-2011-1645Cisco RVS4000和WRVS4400N Web管理界面信息泄露漏洞
CVE-2011-1512IBM Lotus Notes Autonomy KeyView .xls附件处理多个堆缓冲区溢出漏洞
CVE-2011-0546Symantec Backup Exec非法访问漏洞
CVE-2011-1485Red Hat PolicyKit pkexec功能和polkitd守护进程竞争条件漏洞
CVE-2011-1329Walrus_Digit WalRack文件扩展处理任意文件上传漏洞
CVE-2011-1218IBM Lotus Notes Autonomy KeyView .zip附件处理缓冲区溢出漏洞
CVE-2011-1217IBM Lotus Notes Autonomy KeyView .prz附件处理缓冲区溢出漏洞
CVE-2011-1216IBM Lotus Notes Autonomy KeyView Applix电子表格附件处理栈缓冲区溢出漏洞

Showing top 20 of 28 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2011-1945

No comments yet


Leave a comment