LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2004-0112

CVE-2004-0112

CVSS 5 · MEDIUM

Summary

The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read.

CVSS 2.0 breakdown

Base score5 (MEDIUM)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Attack vectorNETWORK
Attack complexityLOW
ConfidentialityNONE
IntegrityNONE
AvailabilityPARTIAL

Weakness type (CWE)

Affected products

Cisco firewall services moduleHp aaa serverHp apache-based web serverSymantec clientless vpn gateway 4400Cisco ciscoworks common management foundationCisco ciscoworks common servicesAvaya converged communications serverAvaya sg200Avaya sg203Avaya sg208Avaya sg5Apple mac os xApple mac os x serverFreebsd freebsdHp hp-uxOpenbsd openbsdRedhat enterprise linuxRedhat enterprise linux desktopRedhat linuxSco openserver
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.

Scroll to Top