First published: Wed May 20 2015(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/nss | 2:3.61-1+deb11u3 2:3.61-1+deb11u4 2:3.87.1-1+deb12u1 2:3.107-1 2:3.108-1 | |
debian/openjdk-8 | 8u442-ga-2 | |
debian/openssl | 1.1.1w-0+deb11u1 1.1.1w-0+deb11u2 3.0.15-1~deb12u1 3.0.14-1~deb12u2 3.4.0-2 3.4.1-1 | |
OpenSSL libcrypto | >=1.0.1<=1.0.1m | |
OpenSSL libcrypto | >=1.0.2<=1.0.2a | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =14.10 | |
Ubuntu | =15.04 | |
All of | ||
OpenSSL libcrypto | <=1.0.1m | |
HPE HP-UX | =b.11.31 | |
IBM Content Manager Enterprise | =8.5 | |
BEA JRockit | =r28.3.6 | |
Debian | =7.0 | |
Debian | =8.0 | |
Oracle JDK 6 | =1.6.0-update95 | |
Oracle JDK 6 | =1.7.0-update75 | |
Oracle JDK 6 | =1.7.0-update80 | |
Oracle JDK 6 | =1.8.0-update_33 | |
Oracle JDK 6 | =1.8.0-update45 | |
Oracle Java Runtime Environment (JRE) | =1.6.0-update_95 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update_75 | |
Oracle Java Runtime Environment (JRE) | =1.7.0-update_80 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_33 | |
Oracle Java Runtime Environment (JRE) | =1.8.0-update_45 | |
SUSE Linux Enterprise Desktop with Beagle | =12 | |
SUSE Linux Enterprise Server | =11.0-sp4 | |
SUSE Linux Enterprise Software Development Kit | =12 | |
SUSE Linux Enterprise Server | =12 | |
iOS | <=8.3 | |
Apple iOS and macOS | <=10.10.3 | |
Mozilla NSS ESR | =3.19 | |
Oracle SPARC OPL Service Processor | <=1121 | |
Apple Mobile Safari | ||
Google Chrome | ||
Internet Explorer | ||
Mozilla Firefox | ||
Opera | ||
Mozilla Firefox | =38.1.0 | |
Mozilla Firefox | =39.0 | |
Mozilla Firefox ESR | =31.8 | |
Mozilla SeaMonkey | =2.35 | |
Mozilla Thunderbird | =31.8 | |
Mozilla Thunderbird | =38.1 | |
Mozilla Firefox OS | =2.2 | |
OpenSSL libcrypto | <=1.0.1m | |
HPE HP-UX | =b.11.31 | |
Mozilla Firefox ESR | =38.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-4000 is classified as a medium severity vulnerability due to its potential for man-in-the-middle attacks.
To fix CVE-2015-4000, disable DHE_EXPORT ciphersuites or upgrade to a version of the affected software that does not allow such ciphers.
CVE-2015-4000 affects multiple software packages including OpenSSL, NSS, and various versions of Oracle JDK and Debian Linux.
CVE-2015-4000 enables man-in-the-middle attacks through cipher-downgrade vulnerabilities.
CVE-2015-4000 remains a concern in modern systems that use outdated libraries or configurations allowing DHE_EXPORT ciphers.