ID

VAR-201505-0233


CVE

CVE-2015-4000


TITLE

TLS Encryption problem vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-201505-428

DESCRIPTION

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue. TLS (full name Transport Layer Security, Secure Transport Layer Protocol) is a set of protocols used to provide confidentiality and data integrity between two communication applications. There is a security vulnerability in the TLS protocol 1.2 and earlier versions. The vulnerability comes from that when the server enables the DHE_EXPORT cipher suite, the program does not pass the DHE_EXPORT option correctly. Attackers can exploit this vulnerability to implement man-in-the-middle attacks and cipher-downgrade attacks by rewriting ClientHello (use DHE_EXPORT instead of DHE) and then rewrite ServerHello (use DHE instead of DHE_EXPORT). v9.1x, v9.2x, v10.0x HP Network Node Manager iSPI Performance for QA v9.0x, v9.1x, v9.2x, v10.0x HP Network Node Manager iSPI for IP Multicast QA v9.0x, v9.1x, v9.2x, v10.0x HP Network Node Manager iSPI for MPLS VPN v9.0x, v9.1x, v9.2x, v10.0x HP Network Node Manager iSPI for IP Telephony v9.0x, v9.1x, v9.2x, v10.0x HP Network Node Manager iSPI for NET v9.0x, v9.1x, v9.2x, v10.0x HP Network Node Manager iSPI Performance for Metrics v9.0x, v9.1x, v9.2x, v10.0x HP Network Node Manager iSPI Performance for Traffic v9.0x, v9.1x, v9.2x, v10.0x BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2015-4000 (AV:N/AC:M/Au:N/C:P/I:N/A:N) 4.3 CVE-2015-2808 (AV:N/AC:M/Au:N/C:P/I:N/A:N) 4.3 CVE-2015-0204 (AV:N/AC:M/Au:N/C:P/I:N/A:N) 4.3 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION HP has provided the following updates for HP Network Node Manager i and Smart Plugins (iSPIs) HP Network Node Manager i and Smart Plugins (iSPIs) Version Link to update for CVE-2015-4000 (LogJam) HP Network Node Manager i version v9.1x, v9.2x iSPI Performance for QA iSPI for IP Multicast iSPI for MPLS VPN iSPI for IP Telephony https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetse arch/document/KM01704653 HP Network Node Manager iSPI for Metrics v9.1x, v9.2x https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetse arch/document/KM01740484 HP Network Node Manager iSPI for Traffic v9.1x, v9.2x https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetse arch/document/KM01740489 Note: v10.x is not affected by LogJam HP Network Node Manager i and Smart Plugins (iSPIs) Version Link to update for CVE-2015-2808 (Bar Mitzvah) HP Network Node Manager i version v9.1x, v9.2x, v10.x iSPI Performance for QA iSPI for IP Multicast iSPI for MPLS VPN iSPI for IP Telephony https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetse arch/document/KM01704651 HP Network Node Manager iSPI for Metrics v9.1x, v9.2x, v10.0x https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetse arch/document/KM01740486 HP Network Node Manager iSPI for Traffic v9.1x, v9.2x, v10.0x https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetse arch/document/KM01740487 HP Network Node Manager i and Smart Plugins (iSPIs) Version Link to update for CVE-2015-0204 (Freak) HP Network Node Manager i version v9.x, v10.x iSPI Performance for QA iSPI for IP Multicast iSPI for MPLS VPN iSPI for IP Telephony https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetse arch/document/KM01704633https://softwaresupport.hp.com/group/softwaresupport/ search-result/-/facetsearch/document/KM01704633 HP Network Node Manager iSPI for Metrics v9.1x, v9.2x https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetse arch/document/KM01740481 HP Network Node Manager iSPI for Traffic v9.1x, v9.2x https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetse arch/document/KM01740488 Note: v10.x is not affected by FREAK HISTORY Version:1 (rev.1) - 20 August 2015 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. For the oldstable distribution (wheezy), these problems have been fixed in version 6b36-1.13.8-1~deb7u1. We recommend that you upgrade your openjdk-6 packages. HP Performance Manager v9.0x and v9.20. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201701-46 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Mozilla Network Security Service (NSS): Multiple vulnerabilities Date: January 19, 2017 Bugs: #550288, #571086, #604916 ID: 201701-46 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been found in NSS, the worst of which could allow remote attackers to obtain access to private key information. Background ========== The Mozilla Network Security Service (NSS) is a library implementing security features like SSL v.2/v.3, TLS, PKCS #5, PKCS #7, PKCS #11, PKCS #12, S/MIME and X.509 certificates. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/nss < 3.28 >= 3.28 Description =========== Multiple vulnerabilities have been discovered in NSS. Please review the CVE identifiers and technical papers referenced below for details. Impact ====== Remote attackers could conduct man-in-the-middle attacks, obtain access to private key information, or cause a Denial of Service condition. Workaround ========== There is no known workaround at this time. Resolution ========== All NSS users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/nss-3.28" References ========== [ 1 ] CVE-2015-2721 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-2721 [ 2 ] CVE-2015-4000 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-4000 [ 3 ] CVE-2015-7575 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-7575 [ 4 ] CVE-2016-1938 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1938 [ 5 ] CVE-2016-5285 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-5285 [ 6 ] CVE-2016-8635 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-8635 [ 7 ] CVE-2016-9074 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9074 [ 8 ] SLOTH Attack Technical Paper http://www.mitls.org/pages/attacks/SLOTH Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201701-46 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 --IaUA2rjNRE1qkoRse7wxSpqjKrtacOEtO-- . HP Service Manager Software 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40 Server BACKGROUND CVSS Base Metrics ================= Reference, CVSS V3 Score/Vector, CVSS V2 Score/Vector CVE-2015-4000 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N) Information on CVSS is documented in HPE Customer Notice HPSN-2008-002 here: https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay/?docI d=emr_na-c01345499 RESOLUTION HPE has made the following mitigation information available to resolve the vulnerability for the impacted versions of HPE Service Manager: https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facetse arch/document/KM01728543 For versions 9.30, 9.31, 9.32, 9.33, 9.34 please: Upgrade to SM 9.35.P4 (recommended) or SM 9.34.P5 SM9.35 P4 package, SM 9.35 AIX Server 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143332 SM 9.35 HP Itanium Server 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143206 SM 9.35 HP Itanium Server for Oracle 12c 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143388 SM 9.35 Linux Server 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143530 SM 9.35 Solaris Server 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143276 SM 9.35 Windows Server 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143589 SM 9.34.P5 package, AIX Server 9.34.5003 p5 https://softwaresupport.hpe.com/km/KM02310304 HP Itanium Server 9.34.5003 p5 <[https://softwaresupport.hpe.com/km/KM02311066> Linux Server 9.34.5003 p5 https://softwaresupport.hpe.com/km/KM02310566 Solaris Server 9.34.5003 p5 https://softwaresupport.hpe.com/km/KM02311656 Windows Server 9.34.5003 p5 https://softwaresupport.hpe.com/km/KM02310486 For versions 9.35 please: Upgrade to SM 9.35.P4 SM9.35 P4 package, SM 9.35 AIX Server 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143332 SM 9.35 HP Itanium Server 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143206 SM 9.35 HP Itanium Server for Oracle 12c 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143388 SM 9.35 Linux Server 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143530 SM 9.35 Solaris Server 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143276 SM 9.35 Windows Server 9.35.4001 p4 https://softwaresupport.hpe.com/km/KM02143589 For versions 9.40 please: Upgrade to SM 9.41.P3 SM9.41.P3 package, Service Manager 9.41.3016 p3 - Server for AIX https://softwaresupport.hpe.com/km/KM02236813 Service Manager 9.41.3016 p3 - Server for HP-UX/IA https://softwaresupport.hpe.com/km/KM02236897 Service Manager 9.41.3016 p3 - Server for Linux https://softwaresupport.hpe.com/km/KM02236827 Service Manager 9.41.3016 p3 - Server for Solaris https://softwaresupport.hpe.com/km/KM02236843 Service Manager 9.41.3016 p3 - Server for Windows https://softwaresupport.hpe.com/km/KM02236929 HISTORY Version:1 (rev.1) - 1 July 2016 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running Hewlett Packard Enterprise (HPE) software products should be applied in accordance with the customer's patch management policy. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Note: the current version of the following document is available here: https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/ docDisplay?docId=emr_na-c04760669 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c04760669 Version: 1 HPSBUX03388 SSRT102180 rev.1 - HP-UX running OpenSSL, Remote Disclosure of Information NOTICE: The information in this Security Bulletin should be acted upon as soon as possible. Release Date: 2015-08-05 Last Updated: 2015-08-05 Potential Security Impact: Remote disclosure of information Source: Hewlett-Packard Company, HP Software Security Response Team VULNERABILITY SUMMARY A potential security vulnerability has been identified with HP-UX running OpenSSL with SSL/TLS enabled. This is the TLS vulnerability using US export-grade 512-bit keys in Diffie-Hellman key exchange known as Logjam which could be exploited remotely resulting in disclosure of information. References: CVE-2015-4000: DHE man-in-the-middle protection (Logjam). CVE-2015-1788: Malformed ECParameters causes infinite loop. CVE-2015-1790: PKCS7 crash with missing EnvelopedContent CVE-2015-1791: Race condition handling NewSessionTicket CVE-2015-1792: CMS verify infinite loop with unknown hash function CVE-2015-1793: Alternative Chain Certificate Forgery. SSRT102180 SUPPORTED SOFTWARE VERSIONS*: ONLY impacted versions are listed. HP-UX B.11.31 running OpenSSL 1.0.1m or earlier. BACKGROUND CVSS 2.0 Base Metrics =========================================================== Reference Base Vector Base Score CVE-2015-4000 (AV:N/AC:M/Au:N/C:N/I:P/A:N) 4.3 CVE-2015-1788 (AV:N/AC:M/Au:N/C:N/I:N/A:P) 4.3 CVE-2015-1789 (AV:N/AC:M/Au:N/C:N/I:N/A:P) 4.3 CVE-2015-1790 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 CVE-2015-1791 (AV:N/AC:M/Au:N/C:P/I:P/A:P) 6.8 CVE-2015-1792 (AV:N/AC:L/Au:N/C:N/I:N/A:P) 5.0 CVE-2015-1793 (AV:N/AC:L/Au:N/C:P/I:P/A:N) 6.4 =========================================================== Information on CVSS is documented in HP Customer Notice: HPSN-2008-002 RESOLUTION HP has provided an updated version of OpenSSL to resolve this vulnerability. A new B.11.31 depot for OpenSSL_A.01.00.01p is available here: https://h20392.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber =OPENSSL11I MANUAL ACTIONS: Yes - Update PRODUCT SPECIFIC INFORMATION HP-UX Software Assistant: HP-UX Software Assistant is an enhanced application that replaces HP-UX Security Patch Check. It analyzes all Security Bulletins issued by HP and lists recommended actions that may apply to a specific HP-UX system. It can also download patches and create a depot automatically. For more information see: https://www.hp.com/go/swa The following text is for use by the HP-UX Software Assistant. AFFECTED VERSIONS HP-UX B.11.31 ================== openssl.OPENSSL-CER openssl.OPENSSL-CONF openssl.OPENSSL-DOC openssl.OPENSSL-INC openssl.OPENSSL-LIB openssl.OPENSSL-MAN openssl.OPENSSL-MIS openssl.OPENSSL-PRNG openssl.OPENSSL-PVT openssl.OPENSSL-RUN openssl.OPENSSL-SRC action: install revision A.01.00.01p or subsequent END AFFECTED VERSIONS HISTORY Version:1 (rev.1) - 5 August 2015 Initial release Third Party Security Patches: Third party security patches that are to be installed on systems running HP software products should be applied in accordance with the customer's patch management policy. Support: For issues about implementing the recommendations of this Security Bulletin, contact normal HP Services support channel. For other issues about the content of this Security Bulletin, send e-mail to security-alert@hp.com. Report: To report a potential security vulnerability with any HP supported product, send Email to: security-alert@hp.com Subscribe: To initiate a subscription to receive future HP Security Bulletin alerts via Email: http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins Security Bulletin Archive: A list of recently released Security Bulletins is available here: https://h20564.www2.hp.com/portal/site/hpsc/public/kb/secBullArchive/ Software Product Category: The Software Product Category is represented in the title by the two characters following HPSB. 3C = 3COM 3P = 3rd Party Software GN = HP General Software HF = HP Hardware and Firmware MP = MPE/iX MU = Multi-Platform Software NS = NonStop Servers OV = OpenVMS PI = Printing and Imaging PV = ProCurve ST = Storage Software TU = Tru64 UNIX UX = HP-UX Copyright 2015 Hewlett-Packard Development Company, L.P. Hewlett-Packard Company shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, neither HP or its affiliates, subcontractors or suppliers will be liable for incidental,special or consequential damages including downtime cost; lost profits; damages relating to the procurement of substitute products or services; or damages for loss of data, or software restoration. The information in this document is subject to change without notice. Hewlett-Packard Company and the names of Hewlett-Packard products referenced herein are trademarks of Hewlett-Packard Company in the United States and other countries. Other product and company names mentioned herein may be trademarks of their respective owners. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux) iEYEARECAAYFAlXCSD4ACgkQ4B86/C0qfVlKnQCg5XcK1amrTACEyDY3QtJF75u2 L90AnAgGXxSCZgBVzDQCAezbHbrHPwtg =74KM -----END PGP SIGNATURE----- . ============================================================================ Ubuntu Security Notice USN-2656-2 July 15, 2015 firefox vulnerabilities ============================================================================ A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: USN-2656-1 fixed vulnerabilities in Firefox for Ubuntu 14.04 LTS and later releases. This update provides the corresponding update for Ubuntu 12.04 LTS. Original advisory details: Karthikeyan Bhargavan discovered that NSS incorrectly handled state transitions for the TLS state machine. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to skip the ServerKeyExchange message and remove the forward-secrecy property. (CVE-2015-2721) Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2015-2722, CVE-2015-2733) Bob Clary, Christian Holler, Bobby Holley, Andrew McCreight, Terrence Cole, Steve Fink, Mats Palmgren, Wes Kocher, Andreas Pehrson, Tooru Fujisawa, Andrew Sutherland, and Gary Kwong discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2015-2724, CVE-2015-2725, CVE-2015-2726) Armin Razmdjou discovered that opening hyperlinks with specific mouse and key combinations could allow a Chrome privileged URL to be opened without context restrictions being preserved. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to bypass security restrictions. (CVE-2015-2727) Paul Bandha discovered a type confusion bug in the Indexed DB Manager. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash or execute arbitrary code with the priviliges of the user invoking Firefox. (CVE-2015-2728) Holger Fuhrmannek discovered an out-of-bounds read in Web Audio. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to obtain sensitive information. (CVE-2015-2729) Watson Ladd discovered that NSS incorrectly handled Elliptical Curve Cryptography (ECC) multiplication. A remote attacker could possibly use this issue to spoof ECDSA signatures. (CVE-2015-2730) A use-after-free was discovered when a Content Policy modifies the DOM to remove a DOM object. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash or execute arbitrary code with the priviliges of the user invoking Firefox. (CVE-2015-2731) Ronald Crane discovered multiple security vulnerabilities. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2015-2734, CVE-2015-2735, CVE-2015-2736, CVE-2015-2737, CVE-2015-2738, CVE-2015-2739, CVE-2015-2740) David Keeler discovered that key pinning checks can be skipped when an overridable certificate error occurs. This allows a user to manually override an error for a fake certificate, but cannot be exploited on its own. (CVE-2015-2741) Jonas Jenwald discovered that some internal workers were incorrectly executed with a high privilege. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this in combination with another security vulnerability, to execute arbitrary code in a privileged scope. (CVE-2015-2743) Matthew Green discovered a DHE key processing issue in NSS where a MITM could force a server to downgrade TLS connections to 512-bit export-grade cryptography. An attacker could potentially exploit this to impersonate the server. (CVE-2015-4000) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: firefox 39.0+build5-0ubuntu0.12.04.2 After a standard system update you need to restart Firefox to make all the necessary changes. References: http://www.ubuntu.com/usn/usn-2656-2 http://www.ubuntu.com/usn/usn-2656-1 CVE-2015-2721, CVE-2015-2722, CVE-2015-2724, CVE-2015-2725, CVE-2015-2726, CVE-2015-2727, CVE-2015-2728, CVE-2015-2729, CVE-2015-2730, CVE-2015-2731, CVE-2015-2733, CVE-2015-2734, CVE-2015-2735, CVE-2015-2736, CVE-2015-2737, CVE-2015-2738, CVE-2015-2739, CVE-2015-2740, CVE-2015-2741, CVE-2015-2743, CVE-2015-4000 Package Information: https://launchpad.net/ubuntu/+source/firefox/39.0+build5-0ubuntu0.12.04.2 . These vulnerabilities could be exploited remotely to create a Denial of Service (DoS) and other impacts including..

Trust: 1.89

sources: NVD: CVE-2015-4000 // VULHUB: VHN-81961 // VULMON: CVE-2015-4000 // PACKETSTORM: 133274 // PACKETSTORM: 133234 // PACKETSTORM: 133344 // PACKETSTORM: 140618 // PACKETSTORM: 137744 // PACKETSTORM: 132973 // PACKETSTORM: 132699 // PACKETSTORM: 133990 // PACKETSTORM: 132413

AFFECTED PRODUCTS

vendor:mozillamodel:firefox osscope:eqversion:2.2

Trust: 1.6

vendor:mozillamodel:firefox esrscope:eqversion:31.8

Trust: 1.6

vendor:mozillamodel:thunderbirdscope:eqversion:31.8

Trust: 1.6

vendor:mozillamodel:thunderbirdscope:eqversion:38.1

Trust: 1.6

vendor:mozillamodel:seamonkeyscope:eqversion:2.35

Trust: 1.6

vendor:mozillamodel:firefoxscope:eqversion:39.0

Trust: 1.6

vendor:opensslmodel:opensslscope:gteversion:1.0.1

Trust: 1.0

vendor:susemodel:linux enterprise desktopscope:eqversion:12

Trust: 1.0

vendor:opensslmodel:opensslscope:lteversion:1.0.2a

Trust: 1.0

vendor:hpmodel:hp-uxscope:eqversion:b.11.31

Trust: 1.0

vendor:mozillamodel:network security servicesscope:eqversion:3.19

Trust: 1.0

vendor:oraclemodel:jrockitscope:eqversion:r28.3.6

Trust: 1.0

vendor:applemodel:iphone osscope:lteversion:8.3

Trust: 1.0

vendor:applemodel:mac os xscope:lteversion:10.10.3

Trust: 1.0

vendor:microsoftmodel:internet explorerscope:eqversion: -

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:14.04

Trust: 1.0

vendor:applemodel:safariscope:eqversion: -

Trust: 1.0

vendor:oraclemodel:jdkscope:eqversion:1.6.0

Trust: 1.0

vendor:googlemodel:chromescope:eqversion: -

Trust: 1.0

vendor:oraclemodel:jdkscope:eqversion:1.7.0

Trust: 1.0

vendor:oraclemodel:jrescope:eqversion:1.6.0

Trust: 1.0

vendor:oraclemodel:jrescope:eqversion:1.7.0

Trust: 1.0

vendor:oraclemodel:sparc-opl service processorscope:lteversion:1121

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:7.0

Trust: 1.0

vendor:mozillamodel:firefoxscope:eqversion:38.1.0

Trust: 1.0

vendor:susemodel:linux enterprise serverscope:eqversion:11.0

Trust: 1.0

vendor:operamodel:browserscope:eqversion: -

Trust: 1.0

vendor:oraclemodel:jdkscope:eqversion:1.8.0

Trust: 1.0

vendor:mozillamodel:firefoxscope:eqversion: -

Trust: 1.0

vendor:opensslmodel:opensslscope:gteversion:1.0.2

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:14.10

Trust: 1.0

vendor:oraclemodel:jrescope:eqversion:1.8.0

Trust: 1.0

vendor:opensslmodel:opensslscope:lteversion:1.0.1m

Trust: 1.0

vendor:susemodel:linux enterprise serverscope:eqversion:12

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:12.04

Trust: 1.0

vendor:canonicalmodel:ubuntu linuxscope:eqversion:15.04

Trust: 1.0

vendor:debianmodel:linuxscope:eqversion:8.0

Trust: 1.0

vendor:ibmmodel:content managerscope:eqversion:8.5

Trust: 1.0

vendor:susemodel:linux enterprise software development kitscope:eqversion:12

Trust: 1.0

vendor:mozillamodel:firefox esrscope:eqversion:38.1.0

Trust: 0.6

sources: CNNVD: CNNVD-201505-428 // NVD: CVE-2015-4000

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4000
value: LOW

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2015-4000
value: LOW

Trust: 1.0

CNNVD: CNNVD-201505-428
value: LOW

Trust: 0.6

VULHUB: VHN-81961
value: MEDIUM

Trust: 0.1

VULMON: CVE-2015-4000
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2015-4000
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.1

VULHUB: VHN-81961
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2015-4000
baseSeverity: LOW
baseScore: 3.7
vectorString: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.2
impactScore: 1.4
version: 3.0

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2015-4000
baseSeverity: LOW
baseScore: 3.7
vectorString: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
attackVector: NETWORK
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.2
impactScore: 1.4
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-81961 // VULMON: CVE-2015-4000 // CNNVD: CNNVD-201505-428 // NVD: CVE-2015-4000 // NVD: CVE-2015-4000

PROBLEMTYPE DATA

problemtype:CWE-310

Trust: 1.1

problemtype:CWE-295

Trust: 1.0

sources: VULHUB: VHN-81961 // NVD: CVE-2015-4000

THREAT TYPE

remote

Trust: 0.8

sources: PACKETSTORM: 140618 // PACKETSTORM: 132699 // CNNVD: CNNVD-201505-428

TYPE

encryption problem

Trust: 0.6

sources: CNNVD: CNNVD-201505-428

EXPLOIT AVAILABILITY

sources: VULHUB: VHN-81961

PATCH

title:TLS Fixing measures for protocol encryption problem vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=89458

Trust: 0.6

title:IBM: Security Bulletin: IBM Spectrum Protect Plus vulnerable to Logjam (CVE-2015-4000)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=b088cb485f81aa1e40d469e515f8cc7c

Trust: 0.1

title:IBM: IBM Security Bulletin: Spectrum Protect Operations Center vulnerable to Logjam (CVE-2015-4000)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=9002898279163d9972f239986ab6a5c6

Trust: 0.1

title:IBM: Security Bulletin: IBM Spectrum Protect Backup-Archive Client web user interface, IBM Spectrum Protect for Space Management, and IBM Spectrum Protect for Virtual Environments are vulnerabile to Logjam (CVE-2015-4000)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=b5bf5318623f05f2683ba6f4e835fc5b

Trust: 0.1

title:IBM: Security Bulletin: IBM Spectrum Protect Snapshot for VMware is vulnerable to Logjam (CVE-2015-4000)url:https://vulmon.com/vendoradvisory?qidtp=ibm_psirt_blog&qid=3786c3f564f19ff96adea0022e47fe27

Trust: 0.1

title:Mozilla: NSS accepts export-length DHE keys with regular DHE cipher suitesurl:https://vulmon.com/vendoradvisory?qidtp=mozilla_advisories&qid=af1e71a1de8256659f6ad0f6663d3bee

Trust: 0.1

title:Mozilla: Mozilla Foundation Security Advisory 2015-70url:https://vulmon.com/vendoradvisory?qidtp=mozilla_advisories&qid=2015-70

Trust: 0.1

title:Amazon Linux AMI: ALAS-2015-569url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2015-569

Trust: 0.1

title:Citrix Security Bulletins: CVE-2015-4000 - Citrix Security Advisory for DHE_EXPORT TLS Vulnerabilityurl:https://vulmon.com/vendoradvisory?qidtp=citrix_security_bulletins&qid=84bde745a5fd5d1cca4aceefe7138a6d

Trust: 0.1

title:Ubuntu Security Notice: thunderbird vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-2673-1

Trust: 0.1

title:Debian Security Advisories: DSA-3688-1 nss -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=373dcfd6d281e203a1b020510989c2b1

Trust: 0.1

title:Symantec Security Advisories: SA111 : OpenSSL Vulnerabilities 28-Jan-2016url:https://vulmon.com/vendoradvisory?qidtp=symantec_security_advisories&qid=83d562565218abbdbef42ef8962d127b

Trust: 0.1

title:Amazon Linux AMI: ALAS-2015-550url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2015-550

Trust: 0.1

title:Ubuntu Security Notice: openjdk-7 vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-2696-1

Trust: 0.1

title:Ubuntu Security Notice: openjdk-6 vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-2706-1

Trust: 0.1

title:Debian Security Advisories: DSA-3300-1 iceweasel -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=eee46f11209708fd3b15b41452809324

Trust: 0.1

title:Ubuntu Security Notice: firefox vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-2656-1

Trust: 0.1

title:Debian Security Advisories: DSA-3339-1 openjdk-6 -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=6c93f875c2194ec5cd3ae93ab207dafa

Trust: 0.1

title:Ubuntu Security Notice: firefox vulnerabilitiesurl:https://vulmon.com/vendoradvisory?qidtp=ubuntu_security_notice&qid=USN-2656-2

Trust: 0.1

title:Amazon Linux AMI: ALAS-2015-586url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2015-586

Trust: 0.1

title:Amazon Linux AMI: ALAS-2015-570url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2015-570

Trust: 0.1

title:Symantec Security Advisories: SA98 : OpenSSL Security Advisory 11-June-2015url:https://vulmon.com/vendoradvisory?qidtp=symantec_security_advisories&qid=a7350b0751124b5a44ba8dbd2df71f9f

Trust: 0.1

title:Debian Security Advisories: DSA-3316-1 openjdk-7 -- security updateurl:https://vulmon.com/vendoradvisory?qidtp=debian_security_advisories&qid=6dadb5ef54390af9161ced1370e85421

Trust: 0.1

title:Amazon Linux AMI: ALAS-2015-571url:https://vulmon.com/vendoradvisory?qidtp=amazon_linux_ami&qid=ALAS-2015-571

Trust: 0.1

title:Oracle Solaris Third Party Bulletins: Oracle Solaris Third Party Bulletin - July 2015url:https://vulmon.com/vendoradvisory?qidtp=oracle_solaris_third_party_bulletins&qid=8b701aba68029ec36b631a8e26157a22

Trust: 0.1

title:Citrix Security Bulletins: Multiple Security Vulnerabilities in Citrix NetScaler Platform IPMI Lights Out Management (LOM) firmwareurl:https://vulmon.com/vendoradvisory?qidtp=citrix_security_bulletins&qid=eb059834b7f24e2562bcf592b6d0afbc

Trust: 0.1

title:Oracle Solaris Third Party Bulletins: Oracle Solaris Third Party Bulletin - January 2016url:https://vulmon.com/vendoradvisory?qidtp=oracle_solaris_third_party_bulletins&qid=eb439566c9130adc92d21bc093204cf8

Trust: 0.1

title:Oracle: Oracle Critical Patch Update Advisory - October 2015url:https://vulmon.com/vendoradvisory?qidtp=oracle_advisories&qid=744c19dc9f4f70ad58059bf8733ec9c1

Trust: 0.1

title:Oracle: Oracle Critical Patch Update Advisory - April 2016url:https://vulmon.com/vendoradvisory?qidtp=oracle_advisories&qid=122319027ae43d6d626710f1b1bb1d43

Trust: 0.1

title:Oracle: Oracle Critical Patch Update Advisory - July 2015url:https://vulmon.com/vendoradvisory?qidtp=oracle_advisories&qid=459961024c4bdce7bb3a1a40a65a6f2e

Trust: 0.1

title:Oracle: Oracle Critical Patch Update Advisory - July 2016url:https://vulmon.com/vendoradvisory?qidtp=oracle_advisories&qid=3a04485ebb79f7fbc2472bf9af5ce489

Trust: 0.1

title:Oracle: Oracle Critical Patch Update Advisory - January 2016url:https://vulmon.com/vendoradvisory?qidtp=oracle_advisories&qid=63802a6c83b107c4e6e0c7f9241a66a8

Trust: 0.1

title:nmap-esentireurl:https://github.com/eSentire/nmap-esentire

Trust: 0.1

title:HAProxy-Keepalived-Sec-HighLoadsurl:https://github.com/fatlan/HAProxy-Keepalived-Sec-HighLoads

Trust: 0.1

title:stuffurl:https://github.com/thekondrashov/stuff

Trust: 0.1

title: - url:https://github.com/Live-Hack-CVE/CVE-2015-4000

Trust: 0.1

title: - url:https://github.com/CertifiedCEH/DB

Trust: 0.1

title:Shodan-Browserurl:https://github.com/javirodriguezzz/Shodan-Browser

Trust: 0.1

title:python-ssl-deprecatedurl:https://github.com/yurkao/python-ssl-deprecated

Trust: 0.1

title:a2svurl:https://github.com/84KaliPleXon3/a2sv

Trust: 0.1

title:a2svurl:https://github.com/TheRipperJhon/a2sv

Trust: 0.1

title:Network-Security-2021url:https://github.com/giusepperuggiero96/Network-Security-2021

Trust: 0.1

title:script_a2svurl:https://github.com/F4RM0X/script_a2sv

Trust: 0.1

title:a2svurl:https://github.com/hahwul/a2sv

Trust: 0.1

title:a2svurl:https://github.com/H4CK3RT3CH/a2sv

Trust: 0.1

title:sslscannerurl:https://github.com/fireorb/sslscanner

Trust: 0.1

title:A2SV--SSL-VUL-Scanurl:https://github.com/nyctophile6/A2SV--SSL-VUL-Scan

Trust: 0.1

title:a2svurl:https://github.com/Mre11i0t/a2sv

Trust: 0.1

title:HTTPSScanurl:https://github.com/alexoslabs/HTTPSScan

Trust: 0.1

title: - url:https://github.com/Valdem88/dev-17_ib-yakovlev_vs

Trust: 0.1

sources: VULMON: CVE-2015-4000 // CNNVD: CNNVD-201505-428

EXTERNAL IDS

db:NVDid:CVE-2015-4000

Trust: 2.7

db:SECTRACKid:1032864

Trust: 1.7

db:SECTRACKid:1033341

Trust: 1.7

db:SECTRACKid:1032777

Trust: 1.7

db:SECTRACKid:1032727

Trust: 1.7

db:SECTRACKid:1032871

Trust: 1.7

db:SECTRACKid:1032475

Trust: 1.7

db:SECTRACKid:1032783

Trust: 1.7

db:SECTRACKid:1032653

Trust: 1.7

db:SECTRACKid:1032702

Trust: 1.7

db:SECTRACKid:1033222

Trust: 1.7

db:SECTRACKid:1032865

Trust: 1.7

db:SECTRACKid:1033065

Trust: 1.7

db:SECTRACKid:1033208

Trust: 1.7

db:SECTRACKid:1033019

Trust: 1.7

db:SECTRACKid:1033991

Trust: 1.7

db:SECTRACKid:1032759

Trust: 1.7

db:SECTRACKid:1040630

Trust: 1.7

db:SECTRACKid:1032910

Trust: 1.7

db:SECTRACKid:1033067

Trust: 1.7

db:SECTRACKid:1032637

Trust: 1.7

db:SECTRACKid:1033064

Trust: 1.7

db:SECTRACKid:1032654

Trust: 1.7

db:SECTRACKid:1032656

Trust: 1.7

db:SECTRACKid:1034087

Trust: 1.7

db:SECTRACKid:1032932

Trust: 1.7

db:SECTRACKid:1033385

Trust: 1.7

db:SECTRACKid:1032652

Trust: 1.7

db:SECTRACKid:1032688

Trust: 1.7

db:SECTRACKid:1032699

Trust: 1.7

db:SECTRACKid:1032649

Trust: 1.7

db:SECTRACKid:1032960

Trust: 1.7

db:SECTRACKid:1032647

Trust: 1.7

db:SECTRACKid:1032474

Trust: 1.7

db:SECTRACKid:1033210

Trust: 1.7

db:SECTRACKid:1032778

Trust: 1.7

db:SECTRACKid:1033416

Trust: 1.7

db:SECTRACKid:1033891

Trust: 1.7

db:SECTRACKid:1032884

Trust: 1.7

db:SECTRACKid:1032651

Trust: 1.7

db:SECTRACKid:1033760

Trust: 1.7

db:SECTRACKid:1033433

Trust: 1.7

db:SECTRACKid:1032476

Trust: 1.7

db:SECTRACKid:1032784

Trust: 1.7

db:SECTRACKid:1036218

Trust: 1.7

db:SECTRACKid:1032856

Trust: 1.7

db:SECTRACKid:1033430

Trust: 1.7

db:SECTRACKid:1034884

Trust: 1.7

db:SECTRACKid:1032655

Trust: 1.7

db:SECTRACKid:1032650

Trust: 1.7

db:SECTRACKid:1032648

Trust: 1.7

db:SECTRACKid:1033513

Trust: 1.7

db:SECTRACKid:1033209

Trust: 1.7

db:SECTRACKid:1032645

Trust: 1.7

db:SECTRACKid:1034728

Trust: 1.7

db:JUNIPERid:JSA10681

Trust: 1.7

db:JUNIPERid:JSA10727

Trust: 1.7

db:BIDid:91787

Trust: 1.7

db:BIDid:74733

Trust: 1.7

db:MCAFEEid:SB10122

Trust: 1.7

db:OPENWALLid:OSS-SECURITY/2015/05/20/8

Trust: 1.7

db:SIEMENSid:SSA-412672

Trust: 1.7

db:CNNVDid:CNNVD-201505-428

Trust: 0.7

db:AUSCERTid:ESB-2022.0696

Trust: 0.6

db:AUSCERTid:ESB-2019.3475

Trust: 0.6

db:AUSCERTid:ESB-2023.1333

Trust: 0.6

db:PACKETSTORMid:132413

Trust: 0.2

db:PACKETSTORMid:137744

Trust: 0.2

db:PACKETSTORMid:132649

Trust: 0.1

db:PACKETSTORMid:132586

Trust: 0.1

db:PACKETSTORMid:132164

Trust: 0.1

db:PACKETSTORMid:132610

Trust: 0.1

db:PACKETSTORMid:135506

Trust: 0.1

db:PACKETSTORMid:136247

Trust: 0.1

db:PACKETSTORMid:132439

Trust: 0.1

db:PACKETSTORMid:132652

Trust: 0.1

db:PACKETSTORMid:139002

Trust: 0.1

db:PACKETSTORMid:135510

Trust: 0.1

db:PACKETSTORMid:132465

Trust: 0.1

db:PACKETSTORMid:133338

Trust: 0.1

db:PACKETSTORMid:132468

Trust: 0.1

db:PACKETSTORMid:134232

Trust: 0.1

db:PACKETSTORMid:134902

Trust: 0.1

db:PACKETSTORMid:133324

Trust: 0.1

db:PACKETSTORMid:136975

Trust: 0.1

db:PACKETSTORMid:134755

Trust: 0.1

db:VULHUBid:VHN-81961

Trust: 0.1

db:VULMONid:CVE-2015-4000

Trust: 0.1

db:PACKETSTORMid:133274

Trust: 0.1

db:PACKETSTORMid:133234

Trust: 0.1

db:PACKETSTORMid:133344

Trust: 0.1

db:PACKETSTORMid:140618

Trust: 0.1

db:PACKETSTORMid:132973

Trust: 0.1

db:PACKETSTORMid:132699

Trust: 0.1

db:PACKETSTORMid:133990

Trust: 0.1

sources: VULHUB: VHN-81961 // VULMON: CVE-2015-4000 // PACKETSTORM: 133274 // PACKETSTORM: 133234 // PACKETSTORM: 133344 // PACKETSTORM: 140618 // PACKETSTORM: 137744 // PACKETSTORM: 132973 // PACKETSTORM: 132699 // PACKETSTORM: 133990 // PACKETSTORM: 132413 // CNNVD: CNNVD-201505-428 // NVD: CVE-2015-4000

REFERENCES

url:http://support.citrix.com/article/ctx201114

Trust: 2.3

url:https://www.oracle.com/security-alerts/cpujan2021.html

Trust: 2.3

url:https://security.gentoo.org/glsa/201701-46

Trust: 1.8

url:http://www.ubuntu.com/usn/usn-2656-1

Trust: 1.8

url:http://www.ubuntu.com/usn/usn-2656-2

Trust: 1.8

url:http://lists.apple.com/archives/security-announce/2015/jun/msg00001.html

Trust: 1.7

url:http://lists.apple.com/archives/security-announce/2015/jun/msg00002.html

Trust: 1.7

url:http://www.securityfocus.com/bid/74733

Trust: 1.7

url:http://www.securityfocus.com/bid/91787

Trust: 1.7

url:https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf

Trust: 1.7

url:http://aix.software.ibm.com/aix/efixes/security/sendmail_advisory2.asc

Trust: 1.7

url:http://fortiguard.com/advisory/2015-07-09-cve-2015-1793-openssl-alternative-chains-certificate-forgery

Trust: 1.7

url:http://h20564.www2.hpe.com/hpsc/doc/public/display?docid=emr_na-c04876402

Trust: 1.7

url:http://h20564.www2.hpe.com/hpsc/doc/public/display?docid=emr_na-c04949778

Trust: 1.7

url:http://support.apple.com/kb/ht204941

Trust: 1.7

url:http://support.apple.com/kb/ht204942

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21959111

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21959195

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21959325

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21959453

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21959481

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21959517

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21959530

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21959539

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21959636

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21959812

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21960191

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21961717

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21962455

Trust: 1.7

url:http://www-01.ibm.com/support/docview.wss?uid=swg21962739

Trust: 1.7

url:http://www-304.ibm.com/support/docview.wss?uid=swg21958984

Trust: 1.7

url:http://www-304.ibm.com/support/docview.wss?uid=swg21959132

Trust: 1.7

url:http://www-304.ibm.com/support/docview.wss?uid=swg21960041

Trust: 1.7

url:http://www-304.ibm.com/support/docview.wss?uid=swg21960194

Trust: 1.7

url:http://www-304.ibm.com/support/docview.wss?uid=swg21960380

Trust: 1.7

url:http://www-304.ibm.com/support/docview.wss?uid=swg21960418

Trust: 1.7

url:http://www-304.ibm.com/support/docview.wss?uid=swg21962816

Trust: 1.7

url:http://www-304.ibm.com/support/docview.wss?uid=swg21967893

Trust: 1.7

url:http://www.fortiguard.com/advisory/2015-05-20-logjam-attack

Trust: 1.7

url:http://www.mozilla.org/security/announce/2015/mfsa2015-70.html

Trust: 1.7

url:http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html

Trust: 1.7

url:http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html

Trust: 1.7

url:http://www.oracle.com/technetwork/topics/security/bulletinjan2016-2867206.html

Trust: 1.7

url:http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html

Trust: 1.7

url:http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html

Trust: 1.7

url:http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html

Trust: 1.7

url:http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html

Trust: 1.7

url:http://www.solarwinds.com/documentation/storage/storagemanager/docs/releasenotes/releasenotes.htm

Trust: 1.7

url:https://bto.bluecoat.com/security-advisory/sa98

Trust: 1.7

url:https://bugzilla.mozilla.org/show_bug.cgi?id=1138554

Trust: 1.7

url:https://developer.mozilla.org/en-us/docs/mozilla/projects/nss/nss_3.19.1_release_notes

Trust: 1.7

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04770140

Trust: 1.7

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04772190

Trust: 1.7

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04773119

Trust: 1.7

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04773241

Trust: 1.7

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04832246

Trust: 1.7

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04918839

Trust: 1.7

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04923929

Trust: 1.7

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04926789

Trust: 1.7

url:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04740527

Trust: 1.7

url:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c04953655

Trust: 1.7

url:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c05045763

Trust: 1.7

url:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c05128722

Trust: 1.7

url:https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_na-c05193083

Trust: 1.7

url:https://help.ecostruxureit.com/display/public/uadco8x/struxureware+data+center+operation+software+vulnerability+fixes

Trust: 1.7

url:https://openssl.org/news/secadv/20150611.txt

Trust: 1.7

url:https://puppet.com/security/cve/cve-2015-4000

Trust: 1.7

url:https://security.netapp.com/advisory/ntap-20150619-0001/

Trust: 1.7

url:https://support.citrix.com/article/ctx216642

Trust: 1.7

url:https://www-304.ibm.com/support/docview.wss?uid=swg21959745

Trust: 1.7

url:https://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5098403

Trust: 1.7

url:https://www.openssl.org/blog/blog/2015/05/20/logjam-freak-upcoming-changes/

Trust: 1.7

url:https://www.openssl.org/news/secadv_20150611.txt

Trust: 1.7

url:https://www.suse.com/security/cve/cve-2015-4000.html

Trust: 1.7

url:http://www.debian.org/security/2015/dsa-3287

Trust: 1.7

url:http://www.debian.org/security/2015/dsa-3300

Trust: 1.7

url:http://www.debian.org/security/2015/dsa-3316

Trust: 1.7

url:http://www.debian.org/security/2015/dsa-3324

Trust: 1.7

url:http://www.debian.org/security/2015/dsa-3339

Trust: 1.7

url:http://www.debian.org/security/2016/dsa-3688

Trust: 1.7

url:http://lists.fedoraproject.org/pipermail/package-announce/2015-june/159351.html

Trust: 1.7

url:http://lists.fedoraproject.org/pipermail/package-announce/2015-june/159314.html

Trust: 1.7

url:http://lists.fedoraproject.org/pipermail/package-announce/2015-june/160117.html

Trust: 1.7

url:https://security.gentoo.org/glsa/201506-02

Trust: 1.7

url:https://security.gentoo.org/glsa/201512-10

Trust: 1.7

url:https://security.gentoo.org/glsa/201603-11

Trust: 1.7

url:https://h20564.www2.hp.com/hpsc/doc/public/display?docid=emr_na-c04718196

Trust: 1.7

url:https://blog.cloudflare.com/logjam-the-latest-tls-vulnerability-explained/

Trust: 1.7

url:https://weakdh.org/imperfect-forward-secrecy.pdf

Trust: 1.7

url:http://openwall.com/lists/oss-security/2015/05/20/8

Trust: 1.7

url:http://ftp.netbsd.org/pub/netbsd/security/advisories/netbsd-sa2015-008.txt.asc

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1072.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1185.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1197.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1228.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1229.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1230.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1241.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1242.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1243.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1485.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1486.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1488.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1526.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1544.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2015-1604.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2016-1624.html

Trust: 1.7

url:http://rhn.redhat.com/errata/rhsa-2016-2056.html

Trust: 1.7

url:http://www.securitytracker.com/id/1032474

Trust: 1.7

url:http://www.securitytracker.com/id/1032475

Trust: 1.7

url:http://www.securitytracker.com/id/1032476

Trust: 1.7

url:http://www.securitytracker.com/id/1032637

Trust: 1.7

url:http://www.securitytracker.com/id/1032645

Trust: 1.7

url:http://www.securitytracker.com/id/1032647

Trust: 1.7

url:http://www.securitytracker.com/id/1032648

Trust: 1.7

url:http://www.securitytracker.com/id/1032649

Trust: 1.7

url:http://www.securitytracker.com/id/1032650

Trust: 1.7

url:http://www.securitytracker.com/id/1032651

Trust: 1.7

url:http://www.securitytracker.com/id/1032652

Trust: 1.7

url:http://www.securitytracker.com/id/1032653

Trust: 1.7

url:http://www.securitytracker.com/id/1032654

Trust: 1.7

url:http://www.securitytracker.com/id/1032655

Trust: 1.7

url:http://www.securitytracker.com/id/1032656

Trust: 1.7

url:http://www.securitytracker.com/id/1032688

Trust: 1.7

url:http://www.securitytracker.com/id/1032699

Trust: 1.7

url:http://www.securitytracker.com/id/1032702

Trust: 1.7

url:http://www.securitytracker.com/id/1032727

Trust: 1.7

url:http://www.securitytracker.com/id/1032759

Trust: 1.7

url:http://www.securitytracker.com/id/1032777

Trust: 1.7

url:http://www.securitytracker.com/id/1032778

Trust: 1.7

url:http://www.securitytracker.com/id/1032783

Trust: 1.7

url:http://www.securitytracker.com/id/1032784

Trust: 1.7

url:http://www.securitytracker.com/id/1032856

Trust: 1.7

url:http://www.securitytracker.com/id/1032864

Trust: 1.7

url:http://www.securitytracker.com/id/1032865

Trust: 1.7

url:http://www.securitytracker.com/id/1032871

Trust: 1.7

url:http://www.securitytracker.com/id/1032884

Trust: 1.7

url:http://www.securitytracker.com/id/1032910

Trust: 1.7

url:http://www.securitytracker.com/id/1032932

Trust: 1.7

url:http://www.securitytracker.com/id/1032960

Trust: 1.7

url:http://www.securitytracker.com/id/1033019

Trust: 1.7

url:http://www.securitytracker.com/id/1033064

Trust: 1.7

url:http://www.securitytracker.com/id/1033065

Trust: 1.7

url:http://www.securitytracker.com/id/1033067

Trust: 1.7

url:http://www.securitytracker.com/id/1033208

Trust: 1.7

url:http://www.securitytracker.com/id/1033209

Trust: 1.7

url:http://www.securitytracker.com/id/1033210

Trust: 1.7

url:http://www.securitytracker.com/id/1033222

Trust: 1.7

url:http://www.securitytracker.com/id/1033341

Trust: 1.7

url:http://www.securitytracker.com/id/1033385

Trust: 1.7

url:http://www.securitytracker.com/id/1033416

Trust: 1.7

url:http://www.securitytracker.com/id/1033430

Trust: 1.7

url:http://www.securitytracker.com/id/1033433

Trust: 1.7

url:http://www.securitytracker.com/id/1033513

Trust: 1.7

url:http://www.securitytracker.com/id/1033760

Trust: 1.7

url:http://www.securitytracker.com/id/1033891

Trust: 1.7

url:http://www.securitytracker.com/id/1033991

Trust: 1.7

url:http://www.securitytracker.com/id/1034087

Trust: 1.7

url:http://www.securitytracker.com/id/1034728

Trust: 1.7

url:http://www.securitytracker.com/id/1034884

Trust: 1.7

url:http://www.securitytracker.com/id/1036218

Trust: 1.7

url:http://www.securitytracker.com/id/1040630

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00024.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00026.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00001.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00003.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00004.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00005.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00006.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00007.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00033.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00034.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00046.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00047.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00021.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00017.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00001.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00031.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00040.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-06/msg00023.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-updates/2015-07/msg00016.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00025.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00037.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00039.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00040.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-updates/2015-10/msg00011.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00032.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00037.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00039.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-updates/2016-02/msg00094.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-updates/2016-02/msg00097.html

Trust: 1.7

url:http://www.ubuntu.com/usn/usn-2673-1

Trust: 1.7

url:http://www.ubuntu.com/usn/usn-2696-1

Trust: 1.7

url:http://www.ubuntu.com/usn/usn-2706-1

Trust: 1.7

url:http://marc.info/?l=bugtraq&m=144102017024820&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=143637549705650&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=144060576831314&w=2

Trust: 1.6

url:http://kb.juniper.net/infocenter/index?page=content&id=jsa10681

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=143506486712441&w=2

Trust: 1.6

url:https://support.hpe.com/hpsc/doc/public/display?doclocale=en_us&docid=emr_na-hpesbhf03831en_us

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=144043644216842&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=144050121701297&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=145409266329539&w=2

Trust: 1.6

url:https://kc.mcafee.com/corporate/index?page=content&id=sb10122

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=143880121627664&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=144104533800819&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=144060606031437&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=144061542602287&w=2

Trust: 1.6

url:http://kb.juniper.net/infocenter/index?page=content&id=jsa10727

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=144493176821532&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=143628304012255&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=143655800220052&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=143557934009303&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=144069189622016&w=2

Trust: 1.6

url:http://marc.info/?l=bugtraq&m=143558092609708&w=2

Trust: 1.6

url:https://weakdh.org/

Trust: 1.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-4000

Trust: 0.9

url:https://www.auscert.org.au/bulletins/esb-2022.0696

Trust: 0.6

url:https://www.ibm.com/support/docview.wss?uid=ibm11073000

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2023.1333

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-spectrum-protect-backup-archive-client-web-user-interface-ibm-spectrum-protect-for-space-management-and-ibm-spectrum-protect-for-virtual-environments-are-vulnerabile-to-logjam/

Trust: 0.6

url:https://www.ibm.com/blogs/psirt/security-bulletin-ibm-spectrum-protect-plus-vulnerable-to-logjam-cve-2015-4000/

Trust: 0.6

url:https://www.auscert.org.au/bulletins/esb-2019.3475/

Trust: 0.6

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/secbullarchive/

Trust: 0.5

url:http://h41183.www4.hp.com/signup_alerts.php?jumpid=hpsc_secbulletins

Trust: 0.5

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2015-2808

Trust: 0.4

url:https://nvd.nist.gov/vuln/detail/cve-2015-2721

Trust: 0.2

url:https://www.hp.com/go/swa

Trust: 0.2

url:http://kb.juniper.net/infocenter/index?page=content&amp;id=jsa10681

Trust: 0.1

url:http://kb.juniper.net/infocenter/index?page=content&amp;id=jsa10727

Trust: 0.1

url:https://kc.mcafee.com/corporate/index?page=content&amp;id=sb10122

Trust: 0.1

url:https://support.hpe.com/hpsc/doc/public/display?doclocale=en_us&amp;docid=emr_na-hpesbhf03831en_us

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=143557934009303&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=143628304012255&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=143558092609708&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=143655800220052&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=144060576831314&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=144069189622016&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=144050121701297&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=144060606031437&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=144102017024820&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=144061542602287&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=145409266329539&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=144043644216842&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=143506486712441&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=144104533800819&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=143637549705650&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=143880121627664&amp;w=2

Trust: 0.1

url:http://marc.info/?l=bugtraq&amp;m=144493176821532&amp;w=2

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-0204

Trust: 0.1

url:https://softwaresupport.hp.com/group/softwaresupport/

Trust: 0.1

url:https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facetse

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-4732

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-4748

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2628

Trust: 0.1

url:https://www.debian.org/security/faq

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2632

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-4733

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-4749

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2625

Trust: 0.1

url:https://www.debian.org/security/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-4760

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2601

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2621

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-4731

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2613

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2590

Trust: 0.1

url:https://softwaresupport.hp.com/group/softwaresupport/search-result/-/fa

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-8635

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-4000

Trust: 0.1

url:https://security.gentoo.org/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-7575

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-9074

Trust: 0.1

url:http://www.mitls.org/pages/attacks/sloth

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-9074

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-7575

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-5285

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2015-2721

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-8635

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2016-1938

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-1938

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2016-5285

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://www.hpe.com/support/security_bulletin_archive

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02236843

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02236813

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02143530

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02311066>

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02143589

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02143332

Trust: 0.1

url:https://softwaresupport.hpe.com/group/softwaresupport/search-result/-/facetse

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02310486

Trust: 0.1

url:http://www.hpe.com/support/subscriber_choice

Trust: 0.1

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay?docid=emr_n

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02236827

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02310566

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02310304

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02143206

Trust: 0.1

url:https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docdisplay/?doci

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02143388

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02236897

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02143276

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02311656

Trust: 0.1

url:https://softwaresupport.hpe.com/km/km02236929

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1790

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1789

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1793

Trust: 0.1

url:https://h20392.www2.hp.com/portal/swdepot/displayproductinfo.do?productnumber

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1791

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1788

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-1792

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2733

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2728

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2740

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2737

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2730

Trust: 0.1

url:https://launchpad.net/ubuntu/+source/firefox/39.0+build5-0ubuntu0.12.04.2

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2739

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2734

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2727

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2725

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2731

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2724

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2741

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2735

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2736

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2726

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2722

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2729

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2738

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-2743

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2015-3183

Trust: 0.1

url:http://software.hp.com

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-0118

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-0231

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-0226

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-5704

Trust: 0.1

url:https://h20564.www2.hp.com/portal/site/hpsc/public/kb/

Trust: 0.1

url:https://softwaresupport.hp.com/group/softwaresupport/search-result/-/facets

Trust: 0.1

sources: VULHUB: VHN-81961 // PACKETSTORM: 133274 // PACKETSTORM: 133234 // PACKETSTORM: 133344 // PACKETSTORM: 140618 // PACKETSTORM: 137744 // PACKETSTORM: 132973 // PACKETSTORM: 132699 // PACKETSTORM: 133990 // PACKETSTORM: 132413 // CNNVD: CNNVD-201505-428 // NVD: CVE-2015-4000

CREDITS

HP

Trust: 0.4

sources: PACKETSTORM: 133274 // PACKETSTORM: 133344 // PACKETSTORM: 137744 // PACKETSTORM: 132413

SOURCES

db:VULHUBid:VHN-81961
db:VULMONid:CVE-2015-4000
db:PACKETSTORMid:133274
db:PACKETSTORMid:133234
db:PACKETSTORMid:133344
db:PACKETSTORMid:140618
db:PACKETSTORMid:137744
db:PACKETSTORMid:132973
db:PACKETSTORMid:132699
db:PACKETSTORMid:133990
db:PACKETSTORMid:132413
db:CNNVDid:CNNVD-201505-428
db:NVDid:CVE-2015-4000

LAST UPDATE DATE

2026-06-25T20:08:53.401000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-81961date:2023-02-09T00:00:00
db:VULMONid:CVE-2015-4000date:2023-02-09T00:00:00
db:CNNVDid:CNNVD-201505-428date:2023-03-03T00:00:00
db:NVDid:CVE-2015-4000date:2026-06-17T00:26:36.567

SOURCES RELEASE DATE

db:VULHUBid:VHN-81961date:2015-05-21T00:00:00
db:VULMONid:CVE-2015-4000date:2015-05-21T00:00:00
db:PACKETSTORMid:133274date:2015-08-24T22:05:27
db:PACKETSTORMid:133234date:2015-08-21T16:58:35
db:PACKETSTORMid:133344date:2015-08-27T13:19:00
db:PACKETSTORMid:140618date:2017-01-20T01:24:46
db:PACKETSTORMid:137744date:2016-07-01T13:13:00
db:PACKETSTORMid:132973date:2015-08-06T10:10:00
db:PACKETSTORMid:132699date:2015-07-16T17:45:50
db:PACKETSTORMid:133990date:2015-10-16T01:44:08
db:PACKETSTORMid:132413date:2015-06-23T14:09:34
db:CNNVDid:CNNVD-201505-428date:2015-05-21T00:00:00
db:NVDid:CVE-2015-4000date:2015-05-21T00:59:00.087