CVE Database · CVE-2013-0166
CVSS v3.1
N/A
EPSS
19.65%
Published
Feb 8, 2013
Modified
Apr 28, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.
Weaknesses (CWE)
Affected Products (95)
References (20)
...and 45 more