CVE-2008-0166
HIGH 7.8EPSS 70.7%
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 7.8 HIGH
AV:N/AC:L/Au:N/C:C/I:N/A:N - EPSS
- 70.72% chance of exploitation in the next 30 days, 99th percentile
- Published
- 2008-05-13
- Updated
- 2024-08-07
Proof-of-concept exploits (11)
- http://www.securityfocus.com/archive/1/492112/100/0/threaded
- CVE-2008-0166/dwk_blocklists2★ · 2025-07-25
- CVE-2008-0166/dwk_blocklists_sqlite31★ · 2025-07-25
- CVE-2008-0166/dwklint0★ · 2025-07-25
- CVE-2008-0166/key_generator4★ · 2025-07-24
- CVE-2008-0166/openssl_blocklists2★ · 2021-10-19
- CVE-2008-0166/private_keys3★ · 2025-07-25
- demining/Vulnerable-to-Debian-OpenSSL-bug-CVE-2008-01669★ · 2022-12-07
- g0tmi1k/debian-ssh411★ · 2023-01-22
- shn3rd/OpenSSL-PRNG8★ · 2022-09-05
- Faizan8232403/CVE-Exploit-Research-Development
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/5720
- https://www.exploit-db.com/exploits/5632
- https://www.exploit-db.com/exploits/5622