← Vulnerability feed

Vulnerability record · CVE-2016-7052 · published 26 September 2016

CVE-2016-7052: Novell suse linux enterprise module for web scripting null pointer dereference vulnerability

Novell · Suse Linux Enterprise Module For Web Scripting

crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.

7.5 CVSS 3.1 High EPSS 30% · top 1.8% CWE-476 · NULL pointer dereference
7.5CVSS 3.1 base score, v2 5.0
30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
40References
17 Jun 2026Last modified by NVD

Description

crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21995039 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html PatchThird Party Advisory
http://www.securityfocus.com/bid/93171 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036885 Third Party AdvisoryVDB Entry
https://bto.bluecoat.com/security-advisory/sa132 Third Party Advisory
https://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=6e629b5be45face20b4ca71c4fcbfed78b864a2e
https://kc.mcafee.com/corporate/index?page=content&id=SB10171 Third Party Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:27.openssl.asc Third Party Advisory
https://security.gentoo.org/glsa/201612-16 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03856en_us Third Party Advisory
https://www.openssl.org/news/secadv/20160926.txt Vendor Advisory
https://www.tenable.com/security/tns-2016-16 Third Party Advisory
https://www.tenable.com/security/tns-2016-19 Third Party Advisory
https://www.tenable.com/security/tns-2016-20 Third Party Advisory
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10759 Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2016-10/msg00013.html Third Party Advisory
http://www-01.ibm.com/support/docview.wss?uid=swg21995039 Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html PatchThird Party Advisory
http://www.securityfocus.com/bid/93171 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id/1036885 Third Party AdvisoryVDB Entry
https://bto.bluecoat.com/security-advisory/sa132 Third Party Advisory
https://git.openssl.org/?p=openssl.git%3Ba=commit%3Bh=6e629b5be45face20b4ca71c4fcbfed78b864a2e
https://kc.mcafee.com/corporate/index?page=content&id=SB10171 Third Party Advisory
https://security.FreeBSD.org/advisories/FreeBSD-SA-16:27.openssl.asc Third Party Advisory
https://security.gentoo.org/glsa/201612-16 Third Party Advisory
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03856en_us Third Party Advisory
https://www.openssl.org/news/secadv/20160926.txt Vendor Advisory
https://www.tenable.com/security/tns-2016-16 Third Party Advisory
https://www.tenable.com/security/tns-2016-19 Third Party Advisory
https://www.tenable.com/security/tns-2016-20 Third Party Advisory

Track CVE-2016-7052 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2026-21636Nodejs node.js improper access control vulnerabilityA flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even …EPSS 0.88%10.0CVE-2015-0278Fedoraproject fedora vulnerabilitylibuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.EPSS 3.2%10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 6.5%10.0CVE-2006-3738OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher listOpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The …EPSS 49%analysed9.8CVE-2026-63073Openssl vulnerabilityIssue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the format string to `ERR_raise_da…EPSS 1.2%9.8CVE-2026-48930Nodejs node.js improper access control vulnerabilityA flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolve…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2016-7052), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.