{"cve":{"cve_id":"CVE-2009-3555","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.87264,"epss_percentile":0.99726,"epss_as_of":"2026-06-23","description":"The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context, related to a \"plaintext injection\" attack, aka the \"Project Mogul\" issue.","published_at":"2009-11-09T17:00:00Z","last_modified_at":"2026-06-16T23:11:50.227000Z","cvss_v3_score":9.8,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvss_v3_severity":"CRITICAL","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"poc","ssvc_automatable":true,"ssvc_technical_impact":"total","cwes":["CWE-300"],"nvd_references":["http://lists.apple.com/archives/security-announce/2010//May/msg00001.html","http://www.securitytracker.com/id?1023427","http://support.avaya.com/css/P8/documents/100081611","http://osvdb.org/62210","http://secunia.com/advisories/37640","http://www.arubanetworks.com/support/alerts/aid-020810.txt","http://www.vupen.com/english/advisories/2010/0916","http://support.avaya.com/css/P8/documents/100114327","http://www.redhat.com/support/errata/RHSA-2010-0167.html","http://www.vupen.com/english/advisories/2010/2010","https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html","http://www.vupen.com/english/advisories/2010/0086","http://www.vupen.com/english/advisories/2010/1673","http://www.ietf.org/mail-archive/web/tls/current/msg03948.html","http://secunia.com/advisories/37656","http://www.redhat.com/support/errata/RHSA-2010-0865.html","http://secunia.com/advisories/39628","http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html","http://secunia.com/advisories/42724","http://www.vupen.com/english/advisories/2009/3310","http://www.vupen.com/english/advisories/2009/3205","http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during","http://secunia.com/advisories/39461","http://support.avaya.com/css/P8/documents/100114315","http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c","http://security.gentoo.org/glsa/glsa-201406-32.xml","http://www.ingate.com/Relnote.php?ver=481","http://www.securitytracker.com/id?1023204","http://secunia.com/advisories/40866","http://marc.info/?l=bugtraq&m=134254866602253&w=2","http://www.us-cert.gov/cas/techalerts/TA10-222A.html","http://www.securitytracker.com/id?1023211","http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686","http://secunia.com/advisories/39317","http://www.securitytracker.com/id?1023212","http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html","http://secunia.com/advisories/39127","http://secunia.com/advisories/40545","http://www.vupen.com/english/advisories/2010/3069","http://openbsd.org/errata45.html#010_openssl","http://www.securitytracker.com/id?1023210","http://www.securitytracker.com/id?1023270","http://secunia.com/advisories/40070","http://www.securitytracker.com/id?1023273","http://kbase.redhat.com/faq/docs/DOC-20491","http://www.ubuntu.com/usn/USN-927-5","http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247","http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html","http://www.mandriva.com/security/advisories?name=MDVSA-2010:089","http://www.redhat.com/support/errata/RHSA-2010-0770.html","http://www.openssl.org/news/secadv_20091111.txt","http://www.securitytracker.com/id?1023275","http://www.debian.org/security/2015/dsa-3253","http://www.vupen.com/english/advisories/2009/3484","http://www.securitytracker.com/id?1023207","http://secunia.com/advisories/37859","http://marc.info/?l=bugtraq&m=142660345230545&w=2","http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021752.1-1","http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html","http://www.vupen.com/english/advisories/2010/0848","http://www.openwall.com/lists/oss-security/2009/11/07/3","http://secunia.com/advisories/39819","http://www-01.ibm.com/support/docview.wss?uid=swg1IC68055","http://www.links.org/?p=786","http://osvdb.org/60521","http://www.openwall.com/lists/oss-security/2009/11/23/10","http://www.kb.cert.org/vuls/id/120541","http://www.securitytracker.com/id?1023217","http://www.redhat.com/support/errata/RHSA-2010-0768.html","http://www.vupen.com/english/advisories/2009/3353","http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html","http://secunia.com/advisories/39136","http://www.openoffice.org/security/cves/CVE-2009-3555.html","http://www.vupen.com/english/advisories/2011/0032","http://securitytracker.com/id?1023148","http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html","http://www.securityfocus.com/bid/36935","http://www.tombom.co.uk/blog/?p=85","http://marc.info/?l=bugtraq&m=130497311408250&w=2","http://www.vupen.com/english/advisories/2010/1107","http://www.securitytracker.com/id?1023218","http://www.vupen.com/english/advisories/2010/1350","http://www.redhat.com/support/errata/RHSA-2010-0338.html","http://secunia.com/advisories/42379","https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html","http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml","http://www-01.ibm.com/support/docview.wss?uid=swg1IC67848","http://www.securitytracker.com/id?1023213","http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html","http://www.vupen.com/english/advisories/2010/1793","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617","http://extendedsubset.com/?p=8","http://secunia.com/advisories/37292","http://www.securityfocus.com/archive/1/522176","https://exchange.xforce.ibmcloud.com/vulnerabilities/54158","http://lists.apple.com/archives/security-announce/2010//May/msg00002.html","http://secunia.com/advisories/39278","http://www.securitytracker.com/id?1023205","http://www.redhat.com/support/errata/RHSA-2010-0130.html","http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686","http://marc.info/?l=bugtraq&m=142660345230545&w=2","http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html","http://support.apple.com/kb/HT4004","http://www.securitytracker.com/id?1023215","http://www.ubuntu.com/usn/USN-1010-1","http://www.securitytracker.com/id?1023206","http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html","https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888","http://security.gentoo.org/glsa/glsa-200912-01.xml","http://marc.info/?l=bugtraq&m=127419602507642&w=2","http://www.vupen.com/english/advisories/2009/3313","http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1","http://www.securitytracker.com/id?1023208","http://secunia.com/advisories/43308","http://www.securitytracker.com/id?1023214","http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html","http://secunia.com/advisories/38781","http://marc.info/?l=bugtraq&m=133469267822771&w=2","http://marc.info/?l=bugtraq&m=127419602507642&w=2","http://www.debian.org/security/2009/dsa-1934","https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478","http://www.securitytracker.com/id?1023271","http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html","http://marc.info/?l=cryptography&m=125752275331877&w=2","http://secunia.com/advisories/42467","http://www.securityfocus.com/archive/1/508130/100/0/threaded","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315","http://www.securitytracker.com/id?1023224","http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html","http://www.ubuntu.com/usn/USN-927-4","http://secunia.com/advisories/41490","http://www.securityfocus.com/archive/1/508075/100/0/threaded","http://www.securitytracker.com/id?1023243","http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html","http://secunia.com/advisories/37504","http://www.securitytracker.com/id?1023219","http://sysoev.ru/nginx/patch.cve-2009-3555.txt","http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html","http://www.securitytracker.com/id?1023163","http://marc.info/?l=bugtraq&m=132077688910227&w=2","http://www.vupen.com/english/advisories/2009/3521","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973","http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995","http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released","https://bugzilla.redhat.com/show_bug.cgi?id=533125","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088","http://secunia.com/advisories/44183","http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES","http://secunia.com/advisories/42808","http://secunia.com/advisories/39500","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578","http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html","http://www.vupen.com/english/advisories/2009/3220","http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751","http://marc.info/?l=bugtraq&m=127557596201693&w=2","http://www.redhat.com/support/errata/RHSA-2010-0165.html","http://www.securityfocus.com/archive/1/515055/100/0/threaded","http://www.redhat.com/support/errata/RHSA-2010-0987.html","https://bugzilla.mozilla.org/show_bug.cgi?id=545755","http://www-01.ibm.com/support/docview.wss?uid=swg21426108","http://blogs.iss.net/archive/sslmitmiscsrf.html","http://www.securitytracker.com/id?1023411","http://www.redhat.com/support/errata/RHSA-2010-0339.html","http://www.redhat.com/support/errata/RHSA-2010-0986.html","http://www.vupen.com/english/advisories/2009/3164","http://secunia.com/advisories/37383","https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.html","http://secunia.com/advisories/44954","http://www.ietf.org/mail-archive/web/tls/current/msg03928.html","http://marc.info/?l=bugtraq&m=127557596201693&w=2","http://support.avaya.com/css/P8/documents/100070150","http://secunia.com/advisories/40747","http://marc.info/?l=bugtraq&m=126150535619567&w=2","http://www.securityfocus.com/archive/1/522176","http://secunia.com/advisories/39292","http://secunia.com/advisories/42816","http://www-01.ibm.com/support/docview.wss?uid=swg1IC68054","http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1","https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html","http://www-01.ibm.com/support/docview.wss?uid=swg21432298","http://extendedsubset.com/Renegotiating_TLS.pdf","http://www-01.ibm.com/support/docview.wss?uid=swg24025312","http://www-01.ibm.com/support/docview.wss?uid=swg24006386","http://support.apple.com/kb/HT4170","http://www.securityfocus.com/archive/1/507952/100/0/threaded","http://www.securitytracker.com/id?1023209","http://www-1.ibm.com/support/search.wss?rs=0&q=PM00675&apar=only","http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html","http://marc.info/?l=bugtraq&m=130497311408250&w=2","http://secunia.com/advisories/48577","http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446","http://www.links.org/?p=789","http://www.opera.com/docs/changelogs/unix/1060/","http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html","http://www.redhat.com/support/errata/RHSA-2011-0880.html","http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html","http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html","http://www.openwall.com/lists/oss-security/2009/11/06/3","https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.html","http://wiki.rpath.com/Advisories:rPSA-2009-0155","http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html","http://support.citrix.com/article/CTX123359","http://secunia.com/advisories/37501","http://www.mandriva.com/security/advisories?name=MDVSA-2010:076","http://marc.info/?l=bugtraq&m=127128920008563&w=2","http://www.vupen.com/english/advisories/2009/3587","http://secunia.com/advisories/39632","http://marc.info/?l=bugtraq&m=126150535619567&w=2","http://secunia.com/advisories/38687","https://bugzilla.mozilla.org/show_bug.cgi?id=526689","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049","http://www.vupen.com/english/advisories/2010/0982","http://marc.info/?l=bugtraq&m=133469267822771&w=2","http://secunia.com/advisories/37399","http://www.ubuntu.com/usn/USN-927-1","http://www.securitytracker.com/id?1023272","https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html","http://www.vupen.com/english/advisories/2010/3126","http://secunia.com/advisories/37320","http://www.vupen.com/english/advisories/2009/3165","http://www.vupen.com/english/advisories/2010/1639","http://secunia.com/advisories/38020","http://ubuntu.com/usn/usn-923-1","http://secunia.com/advisories/39243","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366","http://secunia.com/advisories/37453","http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html","http://www.vupen.com/english/advisories/2010/0933","http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995","http://www.vmware.com/security/advisories/VMSA-2011-0003.html","http://secunia.com/advisories/41972","http://www.vupen.com/english/advisories/2010/3086","http://www.debian.org/security/2011/dsa-2141","http://www.securitytracker.com/id?1024789","http://www.redhat.com/support/errata/RHSA-2010-0155.html","http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html","http://www.vupen.com/english/advisories/2011/0033","http://www.redhat.com/support/errata/RHSA-2010-0337.html","http://www.securitytracker.com/id?1023216","http://secunia.com/advisories/41480","http://www.vupen.com/english/advisories/2011/0086","http://secunia.com/advisories/41818","http://secunia.com/advisories/37604","http://www.opera.com/support/search/view/944/","http://marc.info/?l=apache-httpd-announce&m=125755783724966&w=2","http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html","http://www.us-cert.gov/cas/techalerts/TA10-287A.html","http://www.links.org/?p=780","http://www.redhat.com/support/errata/RHSA-2010-0119.html","http://secunia.com/advisories/38056","http://www.vupen.com/english/advisories/2010/0748","http://secunia.com/advisories/37675","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535","http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751","http://marc.info/?l=bugtraq&m=127128920008563&w=2","http://www.vmware.com/security/advisories/VMSA-2010-0019.html","http://www.redhat.com/support/errata/RHSA-2010-0786.html","https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt","http://secunia.com/advisories/38003","http://support.apple.com/kb/HT4171","http://www.securitytracker.com/id?1023428","http://marc.info/?l=bugtraq&m=132077688910227&w=2","http://www.openwall.com/lists/oss-security/2009/11/20/1","http://www.vupen.com/english/advisories/2009/3354","http://www.securitytracker.com/id?1023274","https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.html","http://secunia.com/advisories/39242","https://kb.bluecoat.com/index?page=content&id=SA50","http://secunia.com/advisories/38241","http://secunia.com/advisories/42377","http://security.gentoo.org/glsa/glsa-201203-22.xml","http://www.openwall.com/lists/oss-security/2009/11/05/3","http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html","http://osvdb.org/60972","http://www.securitytracker.com/id?1023426","http://secunia.com/advisories/38484","http://www.mandriva.com/security/advisories?name=MDVSA-2010:084","http://www.betanews.com/article/1257452450","http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021653.1-1","http://www.mozilla.org/security/announce/2010/mfsa2010-22.html","http://www.securityfocus.com/archive/1/516397/100/0/threaded","http://openbsd.org/errata46.html#004_openssl","http://secunia.com/advisories/41967","http://www.redhat.com/support/errata/RHSA-2010-0807.html","http://www.vupen.com/english/advisories/2010/1191","http://seclists.org/fulldisclosure/2009/Nov/139","https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html","http://www.openwall.com/lists/oss-security/2009/11/05/5","http://secunia.com/advisories/39713","http://secunia.com/advisories/42733","http://secunia.com/advisories/37291","http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html","http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html","http://www.vupen.com/english/advisories/2010/2745","http://sunsolve.sun.com/search/document.do?assetkey=1-26-273350-1","http://www.vupen.com/english/advisories/2010/0994","http://www.vupen.com/english/advisories/2010/0173","http://www.vupen.com/english/advisories/2010/1054","http://osvdb.org/65202","http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041","http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html","http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html","http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.html","http://clicky.me/tlsvuln","http://secunia.com/advisories/42811","https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E","https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E"],"vuln_status":"Modified","trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:05:11.276559Z"},"effective_severity":"CRITICAL","badges":["epss"],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"H","value_label":"High"},{"metric":"A","name":"Availability","value":"H","value_label":"High"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"apache","vendor_name":"apache","product_slug":"http-server","product_name":"http_server","version_start":null,"version_start_inclusive":null,"version_end":"2.2.14","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*"},{"vendor_slug":"canonical","vendor_name":"Canonical","product_slug":"ubuntu-linux","product_name":"Ubuntu Linux","version_start":"10.10","version_start_inclusive":true,"version_end":"10.10","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*"},{"vendor_slug":"canonical","vendor_name":"Canonical","product_slug":"ubuntu-linux","product_name":"Ubuntu Linux","version_start":"8.04","version_start_inclusive":true,"version_end":"8.04","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:lts:*:*:*"},{"vendor_slug":"canonical","vendor_name":"Canonical","product_slug":"ubuntu-linux","product_name":"Ubuntu Linux","version_start":"8.10","version_start_inclusive":true,"version_end":"8.10","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*"},{"vendor_slug":"canonical","vendor_name":"Canonical","product_slug":"ubuntu-linux","product_name":"Ubuntu Linux","version_start":"9.04","version_start_inclusive":true,"version_end":"9.04","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*"},{"vendor_slug":"canonical","vendor_name":"Canonical","product_slug":"ubuntu-linux","product_name":"Ubuntu Linux","version_start":"9.10","version_start_inclusive":true,"version_end":"9.10","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:canonical:ubuntu_linux:9.10:*:*:*:*:*:*:*"},{"vendor_slug":"canonical","vendor_name":"Canonical","product_slug":"ubuntu-linux","product_name":"Ubuntu Linux","version_start":"10.04","version_start_inclusive":true,"version_end":"10.04","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:lts:*:*:*"},{"vendor_slug":"debian","vendor_name":"Debian","product_slug":"debian-linux","product_name":"debian_linux","version_start":"6.0","version_start_inclusive":true,"version_end":"6.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*"},{"vendor_slug":"debian","vendor_name":"Debian","product_slug":"debian-linux","product_name":"debian_linux","version_start":"7.0","version_start_inclusive":true,"version_end":"7.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*"},{"vendor_slug":"debian","vendor_name":"Debian","product_slug":"debian-linux","product_name":"debian_linux","version_start":"8.0","version_start_inclusive":true,"version_end":"8.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"},{"vendor_slug":"debian","vendor_name":"Debian","product_slug":"debian-linux","product_name":"debian_linux","version_start":"4.0","version_start_inclusive":true,"version_end":"4.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:debian:debian_linux:4.0:*:*:*:*:*:*:*"},{"vendor_slug":"debian","vendor_name":"Debian","product_slug":"debian-linux","product_name":"debian_linux","version_start":"5.0","version_start_inclusive":true,"version_end":"5.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:debian:debian_linux:5.0:*:*:*:*:*:*:*"},{"vendor_slug":"f5","vendor_name":"F5","product_slug":"nginx","product_name":"NGINX","version_start":"0.1.0","version_start_inclusive":true,"version_end":"0.8.22","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*"},{"vendor_slug":"fedoraproject","vendor_name":"fedoraproject","product_slug":"fedora","product_name":"fedora","version_start":"12","version_start_inclusive":true,"version_end":"12","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:fedoraproject:fedora:12:*:*:*:*:*:*:*"},{"vendor_slug":"fedoraproject","vendor_name":"fedoraproject","product_slug":"fedora","product_name":"fedora","version_start":"14","version_start_inclusive":true,"version_end":"14","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:fedoraproject:fedora:14:*:*:*:*:*:*:*"},{"vendor_slug":"fedoraproject","vendor_name":"fedoraproject","product_slug":"fedora","product_name":"fedora","version_start":"11","version_start_inclusive":true,"version_end":"11","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*"},{"vendor_slug":"fedoraproject","vendor_name":"fedoraproject","product_slug":"fedora","product_name":"fedora","version_start":"13","version_start_inclusive":true,"version_end":"13","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:o:fedoraproject:fedora:13:*:*:*:*:*:*:*"},{"vendor_slug":"gnu","vendor_name":"gnu","product_slug":"gnutls","product_name":"gnutls","version_start":null,"version_start_inclusive":null,"version_end":"2.8.5","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:gnu:gnutls:*:*:*:*:*:*:*:*"},{"vendor_slug":"mozilla","vendor_name":"Mozilla","product_slug":"nss","product_name":"NSS","version_start":null,"version_start_inclusive":null,"version_end":"3.12.4","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:mozilla:nss:*:*:*:*:*:*:*:*"},{"vendor_slug":"openssl","vendor_name":"OpenSSL","product_slug":"openssl","product_name":"OpenSSL","version_start":null,"version_start_inclusive":null,"version_end":"0.9.8k","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*"},{"vendor_slug":"openssl","vendor_name":"OpenSSL","product_slug":"openssl","product_name":"OpenSSL","version_start":"1.0","version_start_inclusive":true,"version_end":"1.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:openssl:openssl:1.0:*:openvms:*:*:*:*:*"}],"exploit_refs":[],"news":[],"references":[{"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00001.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.securitytracker.com/id?1023427","source_type":"MISC","tags":[]},{"url":"http://support.avaya.com/css/P8/documents/100081611","source_type":"MISC","tags":[]},{"url":"http://osvdb.org/62210","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/37640","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.arubanetworks.com/support/alerts/aid-020810.txt","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2010/0916","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://support.avaya.com/css/P8/documents/100114327","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0167.html","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2010/2010","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2010/0086","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2010/1673","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.ietf.org/mail-archive/web/tls/current/msg03948.html","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/37656","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0865.html","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/39628","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/42724","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2009/3310","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2009/3205","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://blogs.sun.com/security/entry/vulnerability_in_tls_protocol_during","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/39461","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://support.avaya.com/css/P8/documents/100114315","source_type":"MISC","tags":[]},{"url":"http://www.proftpd.org/docs/RELEASE_NOTES-1.3.2c","source_type":"MISC","tags":[]},{"url":"http://security.gentoo.org/glsa/glsa-201406-32.xml","source_type":"MISC","tags":[]},{"url":"http://www.ingate.com/Relnote.php?ver=481","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023204","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/40866","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://marc.info/?l=bugtraq&m=134254866602253&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.us-cert.gov/cas/techalerts/TA10-222A.html","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023211","source_type":"MISC","tags":[]},{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/39317","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023212","source_type":"MISC","tags":[]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00005.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://secunia.com/advisories/39127","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/40545","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2010/3069","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://openbsd.org/errata45.html#010_openssl","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023210","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023270","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/40070","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023273","source_type":"MISC","tags":[]},{"url":"http://kbase.redhat.com/faq/docs/DOC-20491","source_type":"MISC","tags":[]},{"url":"http://www.ubuntu.com/usn/USN-927-5","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1PM12247","source_type":"MISC","tags":[]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00014.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:089","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0770.html","source_type":"MISC","tags":[]},{"url":"http://www.openssl.org/news/secadv_20091111.txt","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023275","source_type":"MISC","tags":[]},{"url":"http://www.debian.org/security/2015/dsa-3253","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2009/3484","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023207","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/37859","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://marc.info/?l=bugtraq&m=142660345230545&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021752.1-1","source_type":"MISC","tags":[]},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-May/040652.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.vupen.com/english/advisories/2010/0848","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2009/11/07/3","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://secunia.com/advisories/39819","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC68055","source_type":"MISC","tags":[]},{"url":"http://www.links.org/?p=786","source_type":"MISC","tags":[]},{"url":"http://osvdb.org/60521","source_type":"MISC","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2009/11/23/10","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.kb.cert.org/vuls/id/120541","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023217","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0768.html","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2009/3353","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039561.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://secunia.com/advisories/39136","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.openoffice.org/security/cves/CVE-2009-3555.html","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2011/0032","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://securitytracker.com/id?1023148","source_type":"MISC","tags":[]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00013.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.securityfocus.com/bid/36935","source_type":"MISC","tags":[]},{"url":"http://www.tombom.co.uk/blog/?p=85","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=130497311408250&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.vupen.com/english/advisories/2010/1107","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023218","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2010/1350","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0338.html","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/42379","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html","source_type":"MISC","tags":[]},{"url":"http://www.cisco.com/en/US/products/products_security_advisory09186a0080b01d1d.shtml","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC67848","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023213","source_type":"MISC","tags":[]},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049702.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.vupen.com/english/advisories/2010/1793","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11617","source_type":"MISC","tags":[]},{"url":"http://extendedsubset.com/?p=8","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/37292","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securityfocus.com/archive/1/522176","source_type":"MISC","tags":[]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/54158","source_type":"MISC","tags":[]},{"url":"http://lists.apple.com/archives/security-announce/2010//May/msg00002.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://secunia.com/advisories/39278","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023205","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0130.html","source_type":"MISC","tags":[]},{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01945686","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=142660345230545&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://tomcat.apache.org/native-doc/miscellaneous/changelog-1.1.x.html","source_type":"MISC","tags":[]},{"url":"http://support.apple.com/kb/HT4004","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023215","source_type":"MISC","tags":[]},{"url":"http://www.ubuntu.com/usn/USN-1010-1","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023206","source_type":"MISC","tags":[]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05150888","source_type":"MISC","tags":[]},{"url":"http://security.gentoo.org/glsa/glsa-200912-01.xml","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=127419602507642&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.vupen.com/english/advisories/2009/3313","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-274990-1","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023208","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/43308","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023214","source_type":"MISC","tags":[]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2009-11/msg00009.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://secunia.com/advisories/38781","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://marc.info/?l=bugtraq&m=133469267822771&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://marc.info/?l=bugtraq&m=127419602507642&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.debian.org/security/2009/dsa-1934","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html","source_type":"MISC","tags":[]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7478","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023271","source_type":"MISC","tags":[]},{"url":"http://lists.apple.com/archives/security-announce/2010/Jan/msg00000.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://marc.info/?l=cryptography&m=125752275331877&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://secunia.com/advisories/42467","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securityfocus.com/archive/1/508130/100/0/threaded","source_type":"MISC","tags":[]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7315","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023224","source_type":"MISC","tags":[]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-06/msg00001.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.ubuntu.com/usn/USN-927-4","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/41490","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securityfocus.com/archive/1/508075/100/0/threaded","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023243","source_type":"MISC","tags":[]},{"url":"http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/37504","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023219","source_type":"MISC","tags":[]},{"url":"http://sysoev.ru/nginx/patch.cve-2009-3555.txt","source_type":"MISC","tags":["patch"]},{"url":"http://xss.cx/examples/plesk-reports/plesk-parallels-controlpanel-psa.v.10.3.1_build1013110726.09%20os_redhat.el6-billing-system-plugin-javascript-injection-example-poc-report.html","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023163","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=132077688910227&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.vupen.com/english/advisories/2009/3521","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7973","source_type":"MISC","tags":[]},{"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995","source_type":"MISC","tags":[]},{"url":"http://support.zeus.com/zws/news/2010/01/13/zws_4_3r5_released","source_type":"MISC","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=533125","source_type":"MISC","tags":[]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10088","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/44183","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://support.zeus.com/zws/media/docs/4.3/RELEASE_NOTES","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/42808","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/39500","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11578","source_type":"MISC","tags":[]},{"url":"http://www.oracle.com/technetwork/topics/security/cpuoct2010-175626.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2009/3220","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0165.html","source_type":"MISC","tags":[]},{"url":"http://www.securityfocus.com/archive/1/515055/100/0/threaded","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0987.html","source_type":"MISC","tags":[]},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=545755","source_type":"MISC","tags":[]},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21426108","source_type":"MISC","tags":[]},{"url":"http://blogs.iss.net/archive/sslmitmiscsrf.html","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023411","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0339.html","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0986.html","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2009/3164","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/37383","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01029.html","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/44954","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.ietf.org/mail-archive/web/tls/current/msg03928.html","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=127557596201693&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://support.avaya.com/css/P8/documents/100070150","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/40747","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://marc.info/?l=bugtraq&m=126150535619567&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.securityfocus.com/archive/1/522176","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/39292","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/42816","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg1IC68054","source_type":"MISC","tags":[]},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-273029-1","source_type":"MISC","tags":[]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00645.html","source_type":"MISC","tags":[]},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21432298","source_type":"MISC","tags":[]},{"url":"http://extendedsubset.com/Renegotiating_TLS.pdf","source_type":"MISC","tags":[]},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg24025312","source_type":"MISC","tags":[]},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg24006386","source_type":"MISC","tags":[]},{"url":"http://support.apple.com/kb/HT4170","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securityfocus.com/archive/1/507952/100/0/threaded","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023209","source_type":"MISC","tags":[]},{"url":"http://www-1.ibm.com/support/search.wss?rs=0&q=PM00675&apar=only","source_type":"MISC","tags":[]},{"url":"http://www.vmware.com/support/vsphere4/doc/vsp_vc41_u1_rel_notes.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://marc.info/?l=bugtraq&m=130497311408250&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://secunia.com/advisories/48577","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://slackware.com/security/viewer.php?l=slackware-security&y=2009&m=slackware-security.597446","source_type":"MISC","tags":[]},{"url":"http://www.links.org/?p=789","source_type":"MISC","tags":[]},{"url":"http://www.opera.com/docs/changelogs/unix/1060/","source_type":"MISC","tags":[]},{"url":"http://www.securegoose.org/2009/11/tls-renegotiation-vulnerability-cve.html","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2011-0880.html","source_type":"MISC","tags":[]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-04/msg00001.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.oracle.com/technetwork/topics/security/javacpuoct2010-176258.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.openwall.com/lists/oss-security/2009/11/06/3","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01020.html","source_type":"MISC","tags":[]},{"url":"http://wiki.rpath.com/Advisories:rPSA-2009-0155","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00002.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://support.citrix.com/article/CTX123359","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/37501","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:076","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://marc.info/?l=bugtraq&m=127128920008563&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.vupen.com/english/advisories/2009/3587","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/39632","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://marc.info/?l=bugtraq&m=126150535619567&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://secunia.com/advisories/38687","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://bugzilla.mozilla.org/show_bug.cgi?id=526689","source_type":"MISC","tags":[]},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-049","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2010/0982","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://marc.info/?l=bugtraq&m=133469267822771&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://secunia.com/advisories/37399","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.ubuntu.com/usn/USN-927-1","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023272","source_type":"MISC","tags":[]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00944.html","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2010/3126","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/37320","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2009/3165","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2010/1639","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/38020","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://ubuntu.com/usn/usn-923-1","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/39243","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8366","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/37453","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.hitachi.co.jp/Prod/comp/soft1/security/info/vuls/HS10-030/index.html","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2010/0933","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02512995","source_type":"MISC","tags":[]},{"url":"http://www.vmware.com/security/advisories/VMSA-2011-0003.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/41972","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2010/3086","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.debian.org/security/2011/dsa-2141","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1024789","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0155.html","source_type":"MISC","tags":[]},{"url":"http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2011/0033","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0337.html","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023216","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/41480","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2011/0086","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/41818","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/37604","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.opera.com/support/search/view/944/","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=apache-httpd-announce&m=125755783724966&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00006.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.us-cert.gov/cas/techalerts/TA10-287A.html","source_type":"MISC","tags":[]},{"url":"http://www.links.org/?p=780","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0119.html","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/38056","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2010/0748","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/37675","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A8535","source_type":"MISC","tags":[]},{"url":"http://itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c02273751","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=127128920008563&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.vmware.com/security/advisories/VMSA-2010-0019.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0786.html","source_type":"MISC","tags":[]},{"url":"https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/38003","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://support.apple.com/kb/HT4171","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023428","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=132077688910227&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.openwall.com/lists/oss-security/2009/11/20/1","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.vupen.com/english/advisories/2009/3354","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.securitytracker.com/id?1023274","source_type":"MISC","tags":[]},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00634.html","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/39242","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://kb.bluecoat.com/index?page=content&id=SA50","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/38241","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/42377","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://security.gentoo.org/glsa/glsa-201203-22.xml","source_type":"MISC","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2009/11/05/3","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2010-10/msg00006.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://osvdb.org/60972","source_type":"MISC","tags":[]},{"url":"http://www.securitytracker.com/id?1023426","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/38484","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2010:084","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.betanews.com/article/1257452450","source_type":"MISC","tags":[]},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-77-1021653.1-1","source_type":"MISC","tags":[]},{"url":"http://www.mozilla.org/security/announce/2010/mfsa2010-22.html","source_type":"MISC","tags":[]},{"url":"http://www.securityfocus.com/archive/1/516397/100/0/threaded","source_type":"MISC","tags":[]},{"url":"http://openbsd.org/errata46.html#004_openssl","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/41967","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.redhat.com/support/errata/RHSA-2010-0807.html","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2010/1191","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://seclists.org/fulldisclosure/2009/Nov/139","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://support.f5.com/kb/en-us/solutions/public/10000/700/sol10737.html","source_type":"MISC","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2009/11/05/5","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://secunia.com/advisories/39713","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/42733","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/37291","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049455.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-April/039957.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.vupen.com/english/advisories/2010/2745","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-26-273350-1","source_type":"MISC","tags":[]},{"url":"http://www.vupen.com/english/advisories/2010/0994","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2010/0173","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.vupen.com/english/advisories/2010/1054","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://osvdb.org/65202","source_type":"MISC","tags":[]},{"url":"http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c02436041","source_type":"MISC","tags":[]},{"url":"http://lists.fedoraproject.org/pipermail/package-announce/2010-October/049528.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00029.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://archives.neohapsis.com/archives/bugtraq/2013-11/0120.html","source_type":"MISC","tags":[]},{"url":"http://clicky.me/tlsvuln","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/42811","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E","source_type":"MAILING_LIST","tags":["mailing-list"]}],"timeline":[{"type":"published","at":"2009-11-09T17:00:00Z","label":"CVE published","source":null},{"type":"ssvc_changed","at":"2026-06-24T00:30:43.703670Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:30:43.703670Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-24T00:30:43.703670Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:30:43.703670Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:30:43.703670Z","label":"CVSS score revised","source":"vulnrichment"},{"type":"cvss_changed","at":"2026-06-24T00:30:43.703670Z","label":"CVSS score revised","source":"vulnrichment"}]}