Known vulnerabilities in OpenSSL - page 6

Software: OpenSSL
Software CPE: cpe:2.3:a:openssl_software_foundation:openssl:*:*:*:*:*:*:*:*
Total vulnerabilities: 220
Public exploits: 26
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenSSL OpenSSL is affected by 220 known vulnerabilities: 2 critical, 15 high, 130 medium, 73 low Critical High Medium Low

Vulnerabilities (220)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU51856 - Improper input validation
CVE-2019-10065
CWE-20 Low
No
No
- 10.03.2020 SB20200310148
SB2021040140
#VU23451 - Cryptographic Issues
CVE-2019-1551
CWE-310 Low
No
No
1.0.2u, 1.1.1e 08.12.2019 SB2019120802
SB2019122101
SB2019122807
and 24 more
#VU21045 - Cryptographic Issues
CVE-2019-1563
CWE-310 Low
No
No
1.0.2t, 1.1.0l, 1.1.1d 11.09.2019 SB2019091112
SB2019091202
SB2019092407
and 27 more
#VU21044 - Protection Mechanism Failure
CVE-2019-1549
CWE-693 Low
No
No
1.1.1d 11.09.2019 SB2019091112
SB2019100304
SB2020040729
and 9 more
#VU21043 - Cryptographic Issues
CVE-2019-1547
CWE-310 Low
No
No
1.0.2t, 1.1.0l, 1.1.1d 11.09.2019 SB2019091112
SB2019091202
SB2019092407
and 39 more
#VU19563 - Incorrect Default Permissions
CVE-2019-1552
CWE-276 Low
No
No
- 30.07.2019 SB2019073002
SB2019123106
SB2022102812
and 4 more
#VU51857 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-10066
CWE-79 Low
No
No
- 22.05.2019 SB2019052232
SB2021040141
#VU51858 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-10067
CWE-79 Low
No
No
- 22.05.2019 SB2019052233
SB2021040142
#VU17908 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2019-1543
CWE-327 Low
No
No
1.1.0k, 1.1.1c 06.03.2019 SB2019030602
SB2019040410
SB2019061209
and 13 more
#VU17860 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2019-1559
CWE-327 Low
No
No
1.0.2r 26.02.2019 SB2019022607
SB2019022802
SB2019022809
and 50 more
#VU15723 - Information Exposure Through Timing Discrepancy
CVE-2018-5407
CWE-208 Low
Available
No
1.1.0i 06.11.2018 SB2018110602
SB2018111301
SB2018112201
and 30 more
#VU15668 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0734
CWE-200 Low
No
No
1.0.2q, 1.1.0j, 1.1.1a 01.11.2018 SB2018110102
SB2018112201
SB2018112602
and 39 more
#VU15568 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0735
CWE-200 Low
No
No
1.1.0j, 1.1.1a 29.10.2018 SB2018110102
SB2018112602
SB2018112906
and 8 more
#VU13325 - Improper input validation
CVE-2018-0732
CWE-20 Low
No
No
1.0.2p, 1.1.0i 12.06.2018 SB2018061305
SB2018070906
SB2018073005
and 54 more
#VU11854 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0737
CWE-200 Low
No
No
- 17.04.2018 SB2018041705
SB2018042001
SB2018070301
and 26 more
#VU11294 - Resource exhaustion
CVE-2018-0739
CWE-400 Low
No
No
- 28.03.2018 SB2018032804
SB2018032903
SB2018033002
and 35 more
#VU11293 - Improper Authentication
CVE-2018-0733
CWE-287 Low
No
No
- 28.03.2018 SB2018032804
SB2018071611
SB2018082403
and 5 more
#VU9594 - Improper input validation
CVE-2017-3737
CWE-20 Medium
No
No
- 08.12.2017 SB2017120804
SB2017120902
SB2017121001
and 21 more
#VU2972 - Exposure of sensitive information to an unauthorized actor
CVE-2016-0701
CWE-200 Medium
No
No
- 30.11.-0001 SB2017121702
SB2016012801
SB2018040102
and 10 more
#VU2765 - Exposure of sensitive information to an unauthorized actor
CVE-2015-3193
CWE-200 Low
No
No
- 30.11.-0001 SB2017012707
SB2017012801
SB2018051123
and 7 more


Showing elements 101 - 120 out of 220