Known vulnerabilities in OpenSSL 1.0.2h - page 2

Software: OpenSSL
Version: 1.0.2h
Software CPE: cpe:2.3:a:openssl_software_foundation:openssl:*:*:*:*:*:*:*:*
Total vulnerabilities: 52
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting OpenSSL version 1.0.2h OpenSSL 1.0.2h is affected by 52 vulnerabilities: 2 high, 28 medium, 22 low Critical High Medium Low

Vulnerabilities (52)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU74149 - Security Features
CVE-2023-0466
CWE-254 Low
No
No
1.0.2zh, 1.1.1u, 3.0.9, 3.1.1 28.03.2023 SB2023032241
SB2023040666
SB2023040730
and 86 more
#VU74148 - Improper Verification of Cryptographic Signature
CVE-2023-0465
CWE-347 Low
No
No
1.0.2zh, 1.1.1u, 3.0.9, 3.1.1 28.03.2023 SB2023032241
SB2023040666
SB2023040730
and 100 more
#VU73960 - Resource exhaustion
CVE-2023-0464
CWE-400 Medium
No
No
1.0.2zh, 1.1.1u, 3.0.9, 3.1.1 22.03.2023 SB2023032241
SB2023033057
SB2023033058
and 100 more
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
1.0.2zg, 1.1.1t, 3.0.8 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
1.0.2zg, 1.1.1t, 3.0.8 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
1.0.2zg, 1.1.1t, 3.0.8 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-2068
CWE-78 Medium
No
No
1.0.2zf, 1.1.1p, 3.0.4 21.06.2022 SB2022062120
SB2022062125
SB2022062236
and 135 more
#VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-1292
CWE-78 Medium
Public exploit available
No
1.0.2ze, 1.1.1o, 3.0.3 03.05.2022 SB2022050315
SB2022050436
SB2022050503
and 141 more
#VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-0778
CWE-835 Medium
Public exploit available
No
1.0.2zd, 1.1.1n, 3.0.2 15.03.2022 SB2022031520
SB2022031522
SB2022031611
and 238 more
#VU60166 - Cryptographic Issues
CVE-2021-4160
CWE-310 Low
No
No
1.1.1m, 3.0.1 28.01.2022 SB2022012811
SB2022031611
SB2022042517
and 29 more
#VU56064 - Out-of-bounds read
CVE-2021-3712
CWE-125 Medium
No
No
1.0.2za, 1.1.1l 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 142 more
#VU50745 - Improper input validation
CVE-2021-23840
CWE-20 Medium
No
No
1.0.2y, 1.1.1j 17.02.2021 SB2021021702
SB2021021817
SB2021022420
and 83 more
#VU50740 - NULL Pointer Dereference
CVE-2021-23841
CWE-476 Medium
No
No
1.0.2y, 1.1.1j 17.02.2021 SB2021021702
SB2021021817
SB2021022420
and 66 more
#VU48896 - NULL Pointer Dereference
CVE-2020-1971
CWE-476 Medium
Public exploit available
No
1.0.2x, 1.1.1i 08.12.2020 SB2020120852
SB2020120903
SB2020120905
and 91 more
#VU46573 - Exposure of sensitive information to an unauthorized actor
CVE-2020-1968
CWE-200 Medium
No
No
1.0.2w 10.09.2020 SB2020091011
SB2020121720
SB2021012078
and 22 more
#VU23451 - Cryptographic Issues
CVE-2019-1551
CWE-310 Low
No
No
1.0.2u, 1.1.1e 08.12.2019 SB2019120802
SB2019122101
SB2019122807
and 24 more
#VU21045 - Cryptographic Issues
CVE-2019-1563
CWE-310 Low
No
No
1.0.2t, 1.1.0l, 1.1.1d 11.09.2019 SB2019091112
SB2019091202
SB2019092407
and 27 more
#VU21043 - Cryptographic Issues
CVE-2019-1547
CWE-310 Low
No
No
1.0.2t, 1.1.0l, 1.1.1d 11.09.2019 SB2019091112
SB2019091202
SB2019092407
and 39 more
#VU19563 - Incorrect Default Permissions
CVE-2019-1552
CWE-276 Low
No
No
- 30.07.2019 SB2019073002
SB2019123106
SB2022102812
and 4 more
#VU17860 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2019-1559
CWE-327 Low
No
No
1.0.2r 26.02.2019 SB2019022607
SB2019022802
SB2019022809
and 50 more


Showing elements 21 - 40 out of 52