OpenSSL kayıtları
openssl üreticisine ait 307 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %0,3
- Silahlaştırılmış
- 10 · %3,3
- Pre-auth RCE
- 19
- Düzeltme kaydı olan
- %92,5
- Yayından KEV’e ortanca
- 2949 gün
Tekrar eden sınıflar
- CWE-476 NULL Pointer Dereference32
- CWE-310 Cryptographic Issues29
- CWE-399 Resource Management Errors22
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor15
- CWE-125 Out-of-bounds Read14
- CWE-295 Improper Certificate Validation14
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
307 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2014-0160Silahlaştırılmış | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remopenssl · openssl · CWE-125 | Yüksek7,5 | KEV | %100,0 | 7 Nis 2014 |
65Bu hafta | CVE-2021-3711İstismar yok | SM2 Decryption Buffer Overflowopenssl · openssl · CWE-120 | Kritik9,8 | — | %87,8 | 24 Ağu 2021 |
65Bu hafta | CVE-2003-0545İstismar yok | Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code openssl · openssl · CWE-415 | Kritik9,8 | — | %87,5 | 17 Kas 2003 |
65Bu hafta | CVE-2009-3555Kavram kanıtı | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Kritik9,8 | — | %87,3 | 9 Kas 2009 |
62Bu hafta | CVE-2016-2108İstismar yok | The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a deniaopenssl · openssl · CWE-119 | Kritik9,8 | — | %77,9 | 4 May 2016 |
60Bu hafta | CVE-2016-6309İstismar yok | statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denopenssl · openssl · CWE-416 | Kritik9,8 | — | %70,2 | 26 Eyl 2016 |
58Planlayın | CVE-2022-2068İstismar yok | The c_rehash script allows command injectionopenssl · openssl · CWE-78 | Yüksek7,3 | — | %95,4 | 21 Haz 2022 |
58Planlayın | CVE-2014-0224Silahlaştırılmış | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whiopenssl · openssl · CWE-326 | Yüksek7,4 | — | %95,3 | 5 Haz 2014 |
58Planlayın | CVE-2016-2183Kavram kanıtı | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of apprredhat · jboss enterprise application platform · CWE-200 | Yüksek7,5 | — | %94,7 | 31 Ağu 2016 |
58Planlayın | CVE-2022-3786Kavram kanıtı | X.509 Email Address Variable Length Buffer Overflowopenssl · openssl · CWE-120 | Yüksek7,5 | — | %92,5 | 1 Kas 2022 |
57Planlayın | CVE-2014-0195Silahlaştırılmış | The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properlopenssl · openssl · CWE-120 | Orta6,8 | — | %100,0 | 5 Haz 2014 |
57Planlayın | CVE-2022-3602Kavram kanıtı | X.509 Email Address 4-byte Buffer Overflowopenssl · openssl · CWE-787 | Yüksek7,5 | — | %90,8 | 1 Kas 2022 |
57Planlayın | CVE-2002-0656Kavram kanıtı | Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a largopenssl · openssl | Yüksek7,5 | — | %89,8 | 12 Ağu 2002 |
55Planlayın | CVE-2016-2842İstismar yok | The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memoropenssl · openssl · CWE-119 | Kritik9,8 | — | %53,7 | 3 Mar 2016 |
55Planlayın | CVE-2006-3738İstismar yok | Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspeciopenssl · openssl · CWE-119 | Kritik10,0 | — | %49,3 | 28 Eyl 2006 |
54Planlayın | CVE-2022-1292Kavram kanıtı | The c_rehash script allows command injectionsiemens · brownfield connectivity gateway · CWE-78 | Yüksek7,3 | — | %82,6 | 3 May 2022 |
53Planlayın | CVE-2022-2274Kavram kanıtı | RSA implementation bug in AVX512IFMA instructionsopenssl · openssl · CWE-787 | Kritik9,8 | — | %45,7 | 1 Tem 2022 |
52Planlayın | CVE-2015-1789İstismar yok | The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1openssl · openssl · CWE-119 | Yüksek7,5 | — | %74,5 | 12 Haz 2015 |
52Planlayın | CVE-2022-0778Kavram kanıtı | Infinite loop in BN_mod_sqrt() reachable when parsing certificatesopenssl · openssl · CWE-835 | Yüksek7,5 | — | %73,2 | 15 Mar 2022 |
52Planlayın | CVE-2016-2177İstismar yok | OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a deopenssl · openssl · CWE-190 | Kritik9,8 | — | %44,5 | 19 Haz 2016 |
52Planlayın | CVE-2016-2182İstismar yok | The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attaopenssl · openssl · CWE-787 | Kritik9,8 | — | %44,2 | 16 Eyl 2016 |
51Planlayın | CVE-2008-0166Kavram kanıtı | OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable openssl · openssl · CWE-338 | Yüksek7,5 | — | %70,7 | 13 May 2008 |
51Planlayın | CVE-2014-3512İstismar yok | Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote attackers to cause aopenssl · openssl · CWE-119 | Yüksek7,5 | — | %69,0 | 13 Ağu 2014 |
51Planlayın | CVE-2025-15467Kavram kanıtı | Stack buffer overflow in CMS (Auth)EnvelopedData parsingopenssl · openssl · CWE-787 | Yüksek8,8 | — | %52,4 | 27 Oca 2026 |
50Planlayın | CVE-2016-2107Kavram kanıtı | The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding checopenssl · openssl · CWE-200 | Orta5,9 | — | %89,1 | 4 May 2016 |
- CVE-2014-016090Hemen
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100openssl · openssl7 Nis 2014
- CVE-2021-371165Bu hafta
SM2 Decryption Buffer Overflow
KritikCVSS 9,8İstismar yokEPSS %88openssl · openssl24 Ağu 2021
- CVE-2003-054565Bu hafta
Double free vulnerability in OpenSSL 0.9.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code
KritikCVSS 9,8İstismar yokEPSS %87openssl · openssl17 Kas 2003
- CVE-2009-355565Bu hafta
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
KritikCVSS 9,8Kavram kanıtıEPSS %87apache · http server9 Kas 2009
- CVE-2016-210862Bu hafta
The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denia
KritikCVSS 9,8İstismar yokEPSS %78openssl · openssl4 May 2016
- CVE-2016-630960Bu hafta
statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a den
KritikCVSS 9,8İstismar yokEPSS %70openssl · openssl26 Eyl 2016
- CVE-2022-206858Planlayın
The c_rehash script allows command injection
YüksekCVSS 7,3İstismar yokEPSS %95openssl · openssl21 Haz 2022
- CVE-2014-022458Planlayın
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, whi
YüksekCVSS 7,4SilahlaştırılmışEPSS %95openssl · openssl5 Haz 2014
- CVE-2016-218358Planlayın
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of appr
YüksekCVSS 7,5Kavram kanıtıEPSS %95redhat · jboss enterprise application platform31 Ağu 2016
- CVE-2022-378658Planlayın
X.509 Email Address Variable Length Buffer Overflow
YüksekCVSS 7,5Kavram kanıtıEPSS %92openssl · openssl1 Kas 2022
- CVE-2014-019557Planlayın
The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properl
OrtaCVSS 6,8SilahlaştırılmışEPSS %100openssl · openssl5 Haz 2014
- CVE-2022-360257Planlayın
X.509 Email Address 4-byte Buffer Overflow
YüksekCVSS 7,5Kavram kanıtıEPSS %91openssl · openssl1 Kas 2022
- CVE-2002-065657Planlayın
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a larg
YüksekCVSS 7,5Kavram kanıtıEPSS %90openssl · openssl12 Ağu 2002
- CVE-2016-284255Planlayın
The doapr_outch function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not verify that a certain memor
KritikCVSS 9,8İstismar yokEPSS %54openssl · openssl3 Mar 2016
- CVE-2006-373855Planlayın
Buffer overflow in the SSL_get_shared_ciphers function in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier versions has unspeci
KritikCVSS 10,0İstismar yokEPSS %49openssl · openssl28 Eyl 2006
- CVE-2022-129254Planlayın
The c_rehash script allows command injection
YüksekCVSS 7,3Kavram kanıtıEPSS %83siemens · brownfield connectivity gateway3 May 2022
- CVE-2022-227453Planlayın
RSA implementation bug in AVX512IFMA instructions
KritikCVSS 9,8Kavram kanıtıEPSS %46openssl · openssl1 Tem 2022
- CVE-2015-178952Planlayın
The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1
YüksekCVSS 7,5İstismar yokEPSS %74openssl · openssl12 Haz 2015
- CVE-2022-077852Planlayın
Infinite loop in BN_mod_sqrt() reachable when parsing certificates
YüksekCVSS 7,5Kavram kanıtıEPSS %73openssl · openssl15 Mar 2022
- CVE-2016-217752Planlayın
OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a de
KritikCVSS 9,8İstismar yokEPSS %45openssl · openssl19 Haz 2016
- CVE-2016-218252Planlayın
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote atta
KritikCVSS 9,8İstismar yokEPSS %44openssl · openssl16 Eyl 2016
- CVE-2008-016651Planlayın
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable
YüksekCVSS 7,5Kavram kanıtıEPSS %71openssl · openssl13 May 2008
- CVE-2014-351251Planlayın
Multiple buffer overflows in crypto/srp/srp_lib.c in the SRP implementation in OpenSSL 1.0.1 before 1.0.1i allow remote attackers to cause a
YüksekCVSS 7,5İstismar yokEPSS %69openssl · openssl13 Ağu 2014
- CVE-2025-1546751Planlayın
Stack buffer overflow in CMS (Auth)EnvelopedData parsing
YüksekCVSS 8,8Kavram kanıtıEPSS %52openssl · openssl27 Oca 2026
- CVE-2016-210750Planlayın
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding chec
OrtaCVSS 5,9Kavram kanıtıEPSS %89openssl · openssl4 May 2016