{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-24T00:22:11.101","vulnerabilities":[{"cve":{"id":"CVE-2016-7054","sourceIdentifier":"openssl-security@openssl.org","published":"2017-05-04T19:29:00.257","lastModified":"2026-06-17T00:52:13.763","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue is not considered to be exploitable beyond a DoS."},{"lang":"es","value":"En OpenSSL 1.1.0 anterior a 1.1.0c, las conexiones TLS que utilizan *-CHACHA20-POLY1305 ciphersuites pueden ser víctimas de una denegación de servicio si se corrompe el payload. Esto puede derivar la caída de OpenSSL. Este problema no se considera explotable más allá de una denegación de servicio."}],"affected":[{"source":"openssl-security@openssl.org","affectedData":[{"vendor":"OpenSSL","product":"OpenSSL","versions":[{"version":"openssl-1.1.0","status":"affected"},{"version":"openssl-1.1.0a","status":"affected"},{"version":"openssl-1.1.0b","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:P","baseScore":5.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":10.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-284"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0:*:*:*:*:*:*:*","matchCriteriaId":"73104834-5810-48DD-9B97-549D223853F1"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0a:*:*:*:*:*:*:*","matchCriteriaId":"C9D7A18A-116B-4F68-BEA3-A4E9DDDA55C6"},{"vulnerable":true,"criteria":"cpe:2.3:a:openssl:openssl:1.1.0b:*:*:*:*:*:*:*","matchCriteriaId":"CFC70262-0DCD-4B46-9C96-FD18D0207511"}]}]}],"references":[{"url":"http://www.securityfocus.com/bid/94238","source":"openssl-security@openssl.org","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id/1037261","source":"openssl-security@openssl.org"},{"url":"https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03744en_us","source":"openssl-security@openssl.org"},{"url":"https://www.exploit-db.com/exploits/40899/","source":"openssl-security@openssl.org"},{"url":"https://www.openssl.org/news/secadv/20161110.txt","source":"openssl-security@openssl.org","tags":["Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/94238","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id/1037261","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03744en_us","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.exploit-db.com/exploits/40899/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.openssl.org/news/secadv/20161110.txt","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}}]}