highREV. 01

CVE-2014-0195OpenSSL — Overflow in Datagram Fragment Reassembly

OpenSSL does not check fragment lengths while reassembling handshake messages over datagrams, so any remote peer can overflow a buffer and run code on the client or server it is talking to.

YOUR NEXT MOVE

Upgrade OpenSSL to 0.9.8za, 1.0.0m or 1.0.1h, and check anything speaking the datagram variant.

Read the risk

THE VITAL STATS
CVSS score
—/ 10
No score recorded
EPSS probability
100%
Likelihood of exploitation
Attack complexity
Low
Conditions needed to exploit
Known exploited
Not listed
CVE published
2014-06-05
Exploit published
Not recorded
Confidence
high
Kill chain
execution
MITRE ATT&CK
T1190
Severity
high

Attacker needsA datagram endpoint the attacker can reach

Fixed inOpenSSL 0.9.8za, OpenSSL 1.0.0m, OpenSSL 1.0.1h

Behind the card

5 REFERENCES
Field-level provenanceTRACE THE SOURCES +

Which source supports each field, when it was retrieved, and who extracted it.

FieldsSourceRetrievedExtractorConfidence
exploitation.attack_complexity, exploitation.exploit_available, references, published_atnvd.nist.gov2026-08-07scrty-crds-pipeline/0.1high
epssapi.first.org2026-08-07scrty-crds-pipeline/0.1high
title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisitesnvd.nist.gov2026-08-07claude-codehigh
mitre_attack, summary, exploitation.prerequisitesnvd.nist.gov2026-09-20humanhigh

Printing history

THE RECORD
  1. r1Initial base card

First printing. This card has not been reprinted since publication.

crds:cve-2014-0195 · CRDS 0.1 · Issued 2026-08-07