Known vulnerabilities in LibreSSL
Vendor:
OpenBSD
Software:
LibreSSL
Software CPE:
cpe:2.3:a:openbsd:libressl:*:*:*:*:*:*:*:*
Website:
https://www.openbsd.org
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
4.3.2
4.3.1
4.3.0
4.2.1
4.1.2
4.2.0
4.1.1
4.0.1
4.1.0
4.0.0
3.9.2
3.9.1
3.8.4
3.9.0
3.8.3
3.8.2
3.8.1
3.8.0
3.7.3
3.6.3
3.7.2
3.7.1
3.6.2
3.5.4
3.7.0
3.6.1
3.6.0
3.5.3
3.5.2
3.5.1
3.4.3
3.3.6
3.5.0
3.4.2
3.4.1
3.2.7
3.3.5
3.4.0
3.2.6
3.3.4
3.3.3
3.3.2
3.2.5
3.2.4
3.1.5
3.2.3
3.3.1
3.3.0
3.2.2
3.2.1
3.1.4
3.2.0
3.1.3
3.1.2
3.1.1
3.1.0
3.0.2
3.0.1
3.0.0
2.9.2
2.9.1
2.9.0
2.8.3
2.8.2
2.8.1
2.8.0
2.7.5
2.5.5
2.5.4
2.5.3
2.5.2
2.5.1
2.5.0
2.4.5
2.4.4
2.4.3
2.4.2
2.4.1
2.4.0
2.3.10
2.3.9
2.3.8
2.3.7
2.3.6
2.3.5
2.3.4
2.3.3
2.3.2
2.3.1
2.3.0
2.2.9
2.2.8
2.2.7
2.2.6
2.2.5
2.2.4
2.2.3
2.2.2
2.2.1
2.2.0
2.1.10
2.1.9
2.1.8
2.1.7
2.1.6
2.1.5
2.1.4
2.1.3
2.1.2
2.0.6
2.7.3
2.7.2
2.7.1
2.7.0
2.7.4
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0
2.6.5
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU116213 - Out-of-bounds write CVE-2025-9230 |
CWE-787 | Medium | 4.0.1, 4.1.1 | 01.10.2025 |
SB2025100119 SB2025100132 SB2025100133 and 108 more |
||
| #VU32983 - Improper Certificate Validation CVE-2017-8301 |
CWE-295 | Medium | 2.5.4 | 03.08.2020 |
SB2017042708 SB2017042710 |
||
| #VU34854 - Missing release of memory after effective lifetime CVE-2015-5333 |
CWE-401 | Medium | 2.3.1 | 23.01.2020 |
SB2020012322 |
||
| #VU34855 - Improper input validation CVE-2015-5334 |
CWE-20 | High | 2.3.1 | 23.01.2020 |
SB2020012322 |
||
| #VU14438 - Exposure of sensitive information to an unauthorized actor CVE-2018-12434 |
CWE-200 | Low | 2.6.5, 2.7.4 | 14.08.2018 |
SB2018081621 SB2018090306 SB2018090401 |