U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2015-3195

Change History

Reanalysis by NIST 1/19/2021 12:27:51 PM

Action Type Old Value New Value
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Removed CVSS V3
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

								
						
Changed CPE Configuration
OR
     *cpe:2.3:a:openssl:openssl:0.9.8zg:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0a:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0b:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0c:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0d:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0e:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0f:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0g:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0h:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0i:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0j:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0k:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0l:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0m:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0n:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0o:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0p:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0q:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0r:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.0s:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1a:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1b:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1c:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1d:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1e:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1f:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1g:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1h:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1i:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1j:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1k:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1l:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1m:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1n:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1o:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.1p:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.2:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.2a:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.2b:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.2c:*:*:*:*:*:*:*
     *cpe:2.3:a:openssl:openssl:1.0.2d:*:*:*:*:*:*:*
OR
     *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions up to (excluding) 0.9.8zh
     *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from (including) 1.0.0 up to (excluding) 1.0.0t
     *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from (including) 1.0.1 up to (excluding) 1.0.1q
     *cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* versions from (including) 1.0.2 up to (excluding) 1.0.2e
Changed CPE Configuration
OR
     *cpe:2.3:a:oracle:api_gateway:11.1.2.3.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:api_gateway:11.1.2.4.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:exalogic_infrastructure:1.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:exalogic_infrastructure:2.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:life_sciences_data_hub:2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:sun_ray_software:11.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:transportation_management:6.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:transportation_management:6.2:*:*:*:*:*:*:*
OR
     *cpe:2.3:a:oracle:api_gateway:11.1.2.3.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:api_gateway:11.1.2.4.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:communications_webrtc_session_controller:7.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:communications_webrtc_session_controller:7.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:communications_webrtc_session_controller:7.2:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:exalogic_infrastructure:1.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:exalogic_infrastructure:2.0:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:http_server:11.5.10.2:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:life_sciences_data_hub:2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:sun_ray_software:11.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:transportation_management:6.1:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:transportation_management:6.2:*:*:*:*:*:*:*
     *cpe:2.3:a:oracle:vm_server:3.2:*:*:*:*:*:x86:*
     *cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* versions up to (excluding) 4.3.36
     *cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* versions from (including) 5.0.0 up to (excluding) 5.0.14
     *cpe:2.3:o:oracle:integrated_lights_out_manager_firmware:*:*:*:*:*:*:*:* versions from (including) 3.0 up to (including) 4.0.4
     *cpe:2.3:o:oracle:linux:5:-:*:*:*:*:*:*
     *cpe:2.3:o:oracle:linux:6:-:*:*:*:*:*:*
     *cpe:2.3:o:oracle:linux:7:-:*:*:*:*:*:*
     *cpe:2.3:o:oracle:solaris:10:*:*:*:*:*:*:*
     *cpe:2.3:o:oracle:solaris:11.3:*:*:*:*:*:*:*
Changed CPE Configuration
OR
     *cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* versions up to (including) 10.11.3
OR
     *cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* versions up to (excluding) 10.11.4
Changed CPE Configuration
OR
     *cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
     *cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
     *cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
     *cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
     *cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
     *cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
OR
     *cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:*
     *cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
     *cpe:2.3:o:canonical:ubuntu_linux:15.04:*:*:*:*:*:*:*
     *cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
Changed CPE Configuration
OR
     *cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_eus:7.2:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_eus:7.3:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_eus:7.6:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_tus:7.2:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
OR
     *cpe:2.3:o:redhat:enterprise_linux_desktop:5.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server:5.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_aus:7.2:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_aus:7.3:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_tus:7.2:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_tus:7.3:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_tus:7.6:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_server_tus:7.7:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_workstation:5.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
     *cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:fedoraproject:fedora:22:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
     *cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
     *cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
     *cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
     *cpe:2.3:o:suse:linux_enterprise_server:10:sp4:*:*:ltss:*:*:*
Removed CPE Configuration
OR
     *cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* versions from (including) 4.3.0 up to (including) 4.3.36
     *cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:* versions from (including) 5.0.0 up to (including) 5.0.14

								
						
Changed Reference Type
http://fortiguard.com/advisory/openssl-advisory-december-2015 Third Party Advisory
http://fortiguard.com/advisory/openssl-advisory-december-2015 Broken Link
Changed Reference Type
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/173801.html Mailing List, Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-December/173801.html Third Party Advisory
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2016-2056.html Third Party Advisory
http://rhn.redhat.com/errata/RHSA-2016-2056.html Broken Link
Changed Reference Type
http://www.fortiguard.com/advisory/openssl-advisory-december-2015 Third Party Advisory
http://www.fortiguard.com/advisory/openssl-advisory-december-2015 Broken Link
Changed Reference Type
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html Patch, Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html Third Party Advisory
Changed Reference Type
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html Patch, Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html Third Party Advisory
Changed Reference Type
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html Patch, Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html Third Party Advisory
Changed Reference Type
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html Patch, Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html Third Party Advisory
Changed Reference Type
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html Patch, Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html Third Party Advisory
Changed Reference Type
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html Patch, Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html Third Party Advisory
Changed Reference Type
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html Patch, Third Party Advisory
http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html Third Party Advisory
Changed Reference Type
https://git.openssl.org/?p=openssl.git;a=commit;h=cc598f321fbac9c04da5766243ed55d55948637d Vendor Advisory
https://git.openssl.org/?p=openssl.git;a=commit;h=cc598f321fbac9c04da5766243ed55d55948637d Patch, Vendor Advisory