Known vulnerabilities in OpenSSL - page 5

Software: OpenSSL
Software CPE: cpe:2.3:a:openssl_software_foundation:openssl:*:*:*:*:*:*:*:*
Total vulnerabilities: 220
Public exploits: 26
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenSSL OpenSSL is affected by 220 known vulnerabilities: 2 critical, 15 high, 130 medium, 73 low Critical High Medium Low

Vulnerabilities (220)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-2068
CWE-78 Medium
No
No
1.0.2zf, 1.1.1p, 3.0.4 21.06.2022 SB2022062120
SB2022062125
SB2022062236
and 135 more
#VU62768 - Uncontrolled Memory Allocation
CVE-2022-1473
CWE-789 Low
No
No
3.0.3 03.05.2022 SB2022050315
SB2022050436
SB2022050532
and 18 more
#VU62767 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2022-1434
CWE-300 Low
No
No
3.0.3 03.05.2022 SB2022050315
SB2022050436
SB2022050532
and 10 more
#VU62766 - Security Features
CVE-2022-1343
CWE-254 Medium
No
No
3.0.3 03.05.2022 SB2022050315
SB2022050436
SB2022050532
and 14 more
#VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-1292
CWE-78 Medium
Available
No
1.0.2ze, 1.1.1o, 3.0.3 03.05.2022 SB2022050315
SB2022050436
SB2022050503
and 141 more
#VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-0778
CWE-835 Medium
Available
No
1.0.2zd, 1.1.1n, 3.0.2 15.03.2022 SB2022031520
SB2022031522
SB2022031611
and 238 more
#VU60166 - Cryptographic Issues
CVE-2021-4160
CWE-310 Low
No
No
1.1.1m, 3.0.1 28.01.2022 SB2022012811
SB2022031611
SB2022042517
and 29 more
#VU58906 - Error Handling
CVE-2021-4044
CWE-388 Low
No
Exploited
3.0.1 14.12.2021 SB2021121446
SB2022062216
#VU56064 - Out-of-bounds read
CVE-2021-3712
CWE-125 Medium
No
No
1.0.2za, 1.1.1l 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 142 more
#VU56063 - Memory corruption
CVE-2021-3711
CWE-119 High
No
No
1.1.1l 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 53 more
#VU51733 - NULL Pointer Dereference
CVE-2021-3449
CWE-476 Medium
Available
No
1.1.1k 25.03.2021 SB2021032518
SB2021032602
SB2021032617
and 56 more
#VU51732 - Security Features
CVE-2021-3450
CWE-254 Medium
No
No
1.1.1k 25.03.2021 SB2021032518
SB2021032602
SB2021032617
and 50 more
#VU50745 - Improper input validation
CVE-2021-23840
CWE-20 Medium
No
No
1.0.2y, 1.1.1j 17.02.2021 SB2021021702
SB2021021817
SB2021022420
and 83 more
#VU50744 - Cryptographic Issues
CVE-2021-23839
CWE-310 Low
No
No
1.0.2y 17.02.2021 SB2021021702
SB2021041501
SB2021041502
and 15 more
#VU50740 - NULL Pointer Dereference
CVE-2021-23841
CWE-476 Medium
No
No
1.0.2y, 1.1.1j 17.02.2021 SB2021021702
SB2021021817
SB2021022420
and 66 more
#VU48896 - NULL Pointer Dereference
CVE-2020-1971
CWE-476 Medium
Available
No
1.0.2x, 1.1.1i 08.12.2020 SB2020120852
SB2020120903
SB2020120905
and 91 more
#VU46573 - Exposure of sensitive information to an unauthorized actor
CVE-2020-1968
CWE-200 Medium
No
No
1.0.2w 10.09.2020 SB2020091011
SB2020121720
SB2021012078
and 22 more
#VU27061 - NULL Pointer Dereference
CVE-2020-1967
CWE-476 Medium
Available
No
1.1.1g 21.04.2020 SB2020042130
SB2020042131
SB2020042326
and 19 more
#VU51860 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-16375
CWE-79 Low
No
No
- 19.03.2020 SB2020031945
SB2021040149
#VU51859 - Exposure of sensitive information to an unauthorized actor
CVE-2019-13457
CWE-200 Low
No
No
- 10.03.2020 SB20200310149
SB2021040147


Showing elements 81 - 100 out of 220