Skip to content
Noroxi

OpenSSL records

307 published records for vendor openssl.

Researcher profile

Entered KEV
1 · 0.3%
Weaponized
10 · 3.3%
Pre-auth RCE
19
With a fix record
92.5%
Median publish → KEV
2949 days

All records

307 records
  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    openssl · opensslApr 7, 2014

  • CVE-2021-3711
    65This week

    SM2 Decryption Buffer Overflow

    CriticalCVSS 9.8No exploitEPSS 88%

    openssl · opensslAug 24, 2021

  • CVE-2003-0545
    65This week

    Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code

    CriticalCVSS 9.8No exploitEPSS 87%

    openssl · opensslNov 17, 2003

  • CVE-2009-3555
    65This week

    The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th

    CriticalCVSS 9.8Proof of conceptEPSS 87%

    apache · http serverNov 9, 2009

  • CVE-2016-2108
    62This week

    The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denia

    CriticalCVSS 9.8No exploitEPSS 78%

    openssl · opensslMay 4, 2016

  • CVE-2016-6309
    60This week

    statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a den

    CriticalCVSS 9.8No exploitEPSS 70%

    openssl · opensslSep 26, 2016

  • The c_rehash script allows command injection

    HighCVSS 7.3No exploitEPSS 95%

    openssl · opensslJun 21, 2022

  • OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi

    HighCVSS 7.4WeaponizedEPSS 95%

    openssl · opensslJun 5, 2014

  • The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr

    HighCVSS 7.5Proof of conceptEPSS 95%

    redhat · jboss enterprise application platformAug 31, 2016

  • X.509 Email Address Variable Length Buffer Overflow

    HighCVSS 7.5Proof of conceptEPSS 92%

    openssl · opensslNov 1, 2022

  • The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properl

    MediumCVSS 6.8WeaponizedEPSS 100%

    openssl · opensslJun 5, 2014

  • X.509 Email Address 4-byte Buffer Overflow

    HighCVSS 7.5Proof of conceptEPSS 91%

    openssl · opensslNov 1, 2022

  • Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a larg

    HighCVSS 7.5Proof of conceptEPSS 90%

    openssl · opensslAug 12, 2002

  • The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memor

    CriticalCVSS 9.8No exploitEPSS 54%

    openssl · opensslMar 3, 2016

  • Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspeci

    CriticalCVSS 10.0No exploitEPSS 49%

    openssl · opensslSep 28, 2006

  • The c_rehash script allows command injection

    HighCVSS 7.3Proof of conceptEPSS 83%

    siemens · brownfield connectivity gatewayMay 3, 2022

  • RSA implementation bug in AVX512IFMA instructions

    CriticalCVSS 9.8Proof of conceptEPSS 46%

    openssl · opensslJul 1, 2022

  • The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1

    HighCVSS 7.5No exploitEPSS 74%

    openssl · opensslJun 12, 2015

  • Infinite loop in BN_mod_sqrt() reachable when parsing certificates

    HighCVSS 7.5Proof of conceptEPSS 73%

    openssl · opensslMar 15, 2022

  • OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a de

    CriticalCVSS 9.8No exploitEPSS 45%

    openssl · opensslJun 19, 2016

  • The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote atta

    CriticalCVSS 9.8No exploitEPSS 44%

    openssl · opensslSep 16, 2016

  • OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable

    HighCVSS 7.5Proof of conceptEPSS 71%

    openssl · opensslMay 13, 2008

  • Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote attackers to cause a

    HighCVSS 7.5No exploitEPSS 69%

    openssl · opensslAug 13, 2014

  • Stack buffer overflow in CMS (Auth)EnvelopedData parsing

    HighCVSS 8.8Proof of conceptEPSS 52%

    openssl · opensslJan 27, 2026

  • The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding chec

    MediumCVSS 5.9Proof of conceptEPSS 89%

    openssl · opensslMay 4, 2016