CVE-2014-3566
Patch soon. It has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
SSL 3.0 has a weakness in how it handles encryption padding that allows attackers to decrypt encrypted messages if they can intercept the connection. This flaw, known as POODLE, affects older encryption systems still in use today.
SSL 3.0 implements nondeterministic CBC padding, enabling padding-oracle attacks where a MITM attacker can systematically decrypt ciphertext by observing padding validation responses. Exploitation requires the attacker to intercept and manipulate client-server traffic, typically by forcing protocol downgrade from TLS to SSL 3.0.