Записи OpenSSL
307 опубликованных записей вендора openssl.
Профиль для исследователя
- Попали в KEV
- 1 · 0,3 %
- С эксплойтом
- 10 · 3,3 %
- Pre-auth RCE
- 19
- С записью об исправлении
- 92,5 %
- Медиана: публикация → KEV
- 2949 дн.
Повторяющиеся классы
- CWE-476 NULL Pointer Dereference32
- CWE-310 Cryptographic Issues29
- CWE-399 Resource Management Errors22
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor15
- CWE-125 Out-of-bounds Read14
- CWE-295 Improper Certificate Validation14
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
307 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2014-0160Готовый эксплойт | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Высокая7,5 | KEV | 100,0 % | 7 апр. 2014 г. |
65На этой неделе | CVE-2021-3711Эксплойта нет | SM2 Decryption Buffer Overflowopenssl · openssl · CWE-120 | Критическая9,8 | — | 87,8 % | 24 авг. 2021 г. |
65На этой неделе | CVE-2003-0545Эксплойта нет | Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code openssl · openssl · CWE-415 | Критическая9,8 | — | 87,5 % | 17 нояб. 2003 г. |
65На этой неделе | CVE-2009-3555Proof of concept | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Критическая9,8 | — | 87,3 % | 9 нояб. 2009 г. |
62На этой неделе | CVE-2016-2108Эксплойта нет | The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a deniaopenssl · openssl · CWE-119 | Критическая9,8 | — | 77,9 % | 4 мая 2016 г. |
60На этой неделе | CVE-2016-6309Эксплойта нет | statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denopenssl · openssl · CWE-416 | Критическая9,8 | — | 70,2 % | 26 сент. 2016 г. |
58В плане | CVE-2022-2068Эксплойта нет | The c_rehash script allows command injectionopenssl · openssl · CWE-78 | Высокая7,3 | — | 95,4 % | 21 июн. 2022 г. |
58В плане | CVE-2014-0224Готовый эксплойт | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | Высокая7,4 | — | 95,3 % | 5 июн. 2014 г. |
58В плане | CVE-2016-2183Proof of concept | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprredhat · jboss enterprise application platform · CWE-200 | Высокая7,5 | — | 94,7 % | 31 авг. 2016 г. |
58В плане | CVE-2022-3786Proof of concept | X.509 Email Address Variable Length Buffer Overflowopenssl · openssl · CWE-120 | Высокая7,5 | — | 92,5 % | 1 нояб. 2022 г. |
57В плане | CVE-2014-0195Готовый эксплойт | The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properlopenssl · openssl · CWE-120 | Средняя6,8 | — | 100,0 % | 5 июн. 2014 г. |
57В плане | CVE-2022-3602Proof of concept | X.509 Email Address 4-byte Buffer Overflowopenssl · openssl · CWE-787 | Высокая7,5 | — | 90,8 % | 1 нояб. 2022 г. |
57В плане | CVE-2002-0656Proof of concept | Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a largopenssl · openssl | Высокая7,5 | — | 89,8 % | 12 авг. 2002 г. |
55В плане | CVE-2016-2842Эксплойта нет | The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memoropenssl · openssl · CWE-119 | Критическая9,8 | — | 53,7 % | 3 мар. 2016 г. |
55В плане | CVE-2006-3738Эксплойта нет | Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspeciopenssl · openssl · CWE-119 | Критическая10,0 | — | 49,3 % | 28 сент. 2006 г. |
54В плане | CVE-2022-1292Proof of concept | The c_rehash script allows command injectionsiemens · brownfield connectivity gateway · CWE-78 | Высокая7,3 | — | 82,6 % | 3 мая 2022 г. |
53В плане | CVE-2022-2274Proof of concept | RSA implementation bug in AVX512IFMA instructionsopenssl · openssl · CWE-787 | Критическая9,8 | — | 45,7 % | 1 июл. 2022 г. |
52В плане | CVE-2015-1789Эксплойта нет | The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1openssl · openssl · CWE-119 | Высокая7,5 | — | 74,5 % | 12 июн. 2015 г. |
52В плане | CVE-2022-0778Proof of concept | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | Высокая7,5 | — | 73,2 % | 15 мар. 2022 г. |
52В плане | CVE-2016-2177Эксплойта нет | OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a deopenssl · openssl · CWE-190 | Критическая9,8 | — | 44,5 % | 19 июн. 2016 г. |
52В плане | CVE-2016-2182Эксплойта нет | The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attaopenssl · openssl · CWE-787 | Критическая9,8 | — | 44,2 % | 16 сент. 2016 г. |
51В плане | CVE-2008-0166Proof of concept | OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable openssl · openssl · CWE-338 | Высокая7,5 | — | 70,7 % | 13 мая 2008 г. |
51В плане | CVE-2014-3512Эксплойта нет | Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote attackers to cause aopenssl · openssl · CWE-119 | Высокая7,5 | — | 69,0 % | 13 авг. 2014 г. |
51В плане | CVE-2025-15467Proof of concept | Stack buffer overflow in CMS (Auth)EnvelopedData parsingopenssl · openssl · CWE-787 | Высокая8,8 | — | 52,4 % | 27 янв. 2026 г. |
50В плане | CVE-2016-2107Proof of concept | The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding checopenssl · openssl · CWE-200 | Средняя5,9 | — | 89,1 % | 4 мая 2016 г. |
- CVE-2014-016090Срочно
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %openssl · openssl7 апр. 2014 г.
- CVE-2021-371165На этой неделе
SM2 Decryption Buffer Overflow
КритическаяCVSS 9,8Эксплойта нетEPSS 88 %openssl · openssl24 авг. 2021 г.
- CVE-2003-054565На этой неделе
Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code
КритическаяCVSS 9,8Эксплойта нетEPSS 87 %openssl · openssl17 нояб. 2003 г.
- CVE-2009-355565На этой неделе
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
КритическаяCVSS 9,8Proof of conceptEPSS 87 %apache · http server9 нояб. 2009 г.
- CVE-2016-210862На этой неделе
The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denia
КритическаяCVSS 9,8Эксплойта нетEPSS 78 %openssl · openssl4 мая 2016 г.
- CVE-2016-630960На этой неделе
statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a den
КритическаяCVSS 9,8Эксплойта нетEPSS 70 %openssl · openssl26 сент. 2016 г.
- CVE-2022-206858В плане
The c_rehash script allows command injection
ВысокаяCVSS 7,3Эксплойта нетEPSS 95 %openssl · openssl21 июн. 2022 г.
- CVE-2014-022458В плане
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
ВысокаяCVSS 7,4Готовый эксплойтEPSS 95 %openssl · openssl5 июн. 2014 г.
- CVE-2016-218358В плане
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr
ВысокаяCVSS 7,5Proof of conceptEPSS 95 %redhat · jboss enterprise application platform31 авг. 2016 г.
- CVE-2022-378658В плане
X.509 Email Address Variable Length Buffer Overflow
ВысокаяCVSS 7,5Proof of conceptEPSS 92 %openssl · openssl1 нояб. 2022 г.
- CVE-2014-019557В плане
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properl
СредняяCVSS 6,8Готовый эксплойтEPSS 100 %openssl · openssl5 июн. 2014 г.
- CVE-2022-360257В плане
X.509 Email Address 4-byte Buffer Overflow
ВысокаяCVSS 7,5Proof of conceptEPSS 91 %openssl · openssl1 нояб. 2022 г.
- CVE-2002-065657В плане
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a larg
ВысокаяCVSS 7,5Proof of conceptEPSS 90 %openssl · openssl12 авг. 2002 г.
- CVE-2016-284255В плане
The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memor
КритическаяCVSS 9,8Эксплойта нетEPSS 54 %openssl · openssl3 мар. 2016 г.
- CVE-2006-373855В плане
Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspeci
КритическаяCVSS 10,0Эксплойта нетEPSS 49 %openssl · openssl28 сент. 2006 г.
- CVE-2022-129254В плане
The c_rehash script allows command injection
ВысокаяCVSS 7,3Proof of conceptEPSS 83 %siemens · brownfield connectivity gateway3 мая 2022 г.
- CVE-2022-227453В плане
RSA implementation bug in AVX512IFMA instructions
КритическаяCVSS 9,8Proof of conceptEPSS 46 %openssl · openssl1 июл. 2022 г.
- CVE-2015-178952В плане
The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1
ВысокаяCVSS 7,5Эксплойта нетEPSS 74 %openssl · openssl12 июн. 2015 г.
- CVE-2022-077852В плане
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
ВысокаяCVSS 7,5Proof of conceptEPSS 73 %openssl · openssl15 мар. 2022 г.
- CVE-2016-217752В плане
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a de
КритическаяCVSS 9,8Эксплойта нетEPSS 45 %openssl · openssl19 июн. 2016 г.
- CVE-2016-218252В плане
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote atta
КритическаяCVSS 9,8Эксплойта нетEPSS 44 %openssl · openssl16 сент. 2016 г.
- CVE-2008-016651В плане
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable
ВысокаяCVSS 7,5Proof of conceptEPSS 71 %openssl · openssl13 мая 2008 г.
- CVE-2014-351251В плане
Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote attackers to cause a
ВысокаяCVSS 7,5Эксплойта нетEPSS 69 %openssl · openssl13 авг. 2014 г.
- CVE-2025-1546751В плане
Stack buffer overflow in CMS (Auth)EnvelopedData parsing
ВысокаяCVSS 8,8Proof of conceptEPSS 52 %openssl · openssl27 янв. 2026 г.
- CVE-2016-210750В плане
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding chec
СредняяCVSS 5,9Proof of conceptEPSS 89 %openssl · openssl4 мая 2016 г.