AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2003-0078

MEDIUM · CVSS 5 EPSS 13.72%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2003-03-03 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2003-0078
Severity
MEDIUM
CVSS
5
EPSS
13.72%
OpenSSL

Original Filing — NVD Description

ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."