Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2018-12384
Description:When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv2 used for TLS 1.2 in all versions prior to NSS 3.39. This does not impact TLS 1.3.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2019.1169   1.3.6.1.4.1.25623.1.1.10.2018.0393   1.3.6.1.4.1.25623.1.0.882953   1.3.6.1.4.1.25623.1.0.875081   1.3.6.1.4.1.25623.1.0.875064   1.3.6.1.4.1.25623.1.0.875084   1.3.6.1.4.1.25623.1.0.882961   1.3.6.1.4.1.25623.1.1.2.2018.1358   1.3.6.1.4.1.25623.1.0.875065   1.3.6.1.4.1.25623.1.0.875085   1.3.6.1.4.1.25623.1.0.875074   1.3.6.1.4.1.25623.1.0.875068   1.3.6.1.4.1.25623.1.1.2.2018.1366   1.3.6.1.4.1.25623.1.0.875082  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2018-12384
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html




© 1998-2025 E-Soft Inc. All rights reserved.