Known vulnerabilities in LibreSSL

Vendor: OpenBSD
Software: LibreSSL
Software CPE: cpe:2.3:a:openbsd:libressl:*:*:*:*:*:*:*:*
Total vulnerabilities: 5
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting LibreSSL LibreSSL is affected by 5 known vulnerabilities: 1 high, 3 medium, 1 low Critical High Medium Low

Vulnerabilities (5)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU116213 - Out-of-bounds write
CVE-2025-9230
CWE-787 Medium
No
No
4.0.1, 4.1.1 01.10.2025 SB2025100119
SB2025100132
SB2025100133
and 108 more
#VU32983 - Improper Certificate Validation
CVE-2017-8301
CWE-295 Medium
No
No
2.5.4 03.08.2020 SB2017042708
SB2017042710
#VU34854 - Missing release of memory after effective lifetime
CVE-2015-5333
CWE-401 Medium
No
No
2.3.1 23.01.2020 SB2020012322
#VU34855 - Improper input validation
CVE-2015-5334
CWE-20 High
No
No
2.3.1 23.01.2020 SB2020012322
#VU14438 - Exposure of sensitive information to an unauthorized actor
CVE-2018-12434
CWE-200 Low
No
No
2.6.5, 2.7.4 14.08.2018 SB2018081621
SB2018090306
SB2018090401