The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about NULL Pointer Dereference vulnerabilities in an interactive lesson.
Start learningUpgrade openssl to version 3.4.8, 3.5.9, 3.6.5, 4.0.3 or higher.
Affected versions of this package are vulnerable to NULL Pointer Dereference in the CMP client's handling of a revocation response, which compares the certificate named in the response against an issuer name and serial number that are unset when the revocation was requested by PKCS#10 CSR. An attacker can crash the client process by returning a revocation response that names a certificate. This requires the attacker to operate or have compromised the CMP server, or to hold the message protection secret and sit in a MitM position, and clients that identify the certificate by issuer and serial rather than by CSR are unaffected.