Known vulnerabilities in OpenSSL - page 7

Software: OpenSSL
Software CPE: cpe:2.3:a:openssl_software_foundation:openssl:*:*:*:*:*:*:*:*
Total vulnerabilities: 243
Public exploits: 26
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenSSL OpenSSL is affected by 243 known vulnerabilities: 2 critical, 15 high, 146 medium, 80 low Critical High Medium Low

Vulnerabilities (243)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU27061 - NULL Pointer Dereference
CVE-2020-1967
CWE-476 Medium
Available
No
1.1.1g 21.04.2020 SB2020042130
SB2020042131
SB2020042326
and 19 more
#VU51860 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-16375
CWE-79 Low
No
No
- 19.03.2020 SB2020031945
SB2021040149
#VU51859 - Exposure of sensitive information to an unauthorized actor
CVE-2019-13457
CWE-200 Low
No
No
- 10.03.2020 SB20200310149
SB2021040147
#VU51856 - Improper input validation
CVE-2019-10065
CWE-20 Low
No
No
- 10.03.2020 SB20200310148
SB2021040140
#VU23451 - Cryptographic Issues
CVE-2019-1551
CWE-310 Low
No
No
1.0.2u, 1.1.1e 08.12.2019 SB2019120802
SB2019122101
SB2019122807
and 24 more
#VU21045 - Cryptographic Issues
CVE-2019-1563
CWE-310 Low
No
No
1.0.2t, 1.1.0l, 1.1.1d 11.09.2019 SB2019091112
SB2019091202
SB2019092407
and 27 more
#VU21044 - Protection Mechanism Failure
CVE-2019-1549
CWE-693 Low
No
No
1.1.1d 11.09.2019 SB2019091112
SB2019100304
SB2020040729
and 9 more
#VU21043 - Cryptographic Issues
CVE-2019-1547
CWE-310 Low
No
No
1.0.2t, 1.1.0l, 1.1.1d 11.09.2019 SB2019091112
SB2019091202
SB2019092407
and 39 more
#VU19563 - Incorrect Default Permissions
CVE-2019-1552
CWE-276 Low
No
No
- 30.07.2019 SB2019073002
SB2019123106
SB2022102812
and 4 more
#VU51857 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-10066
CWE-79 Low
No
No
- 22.05.2019 SB2019052232
SB2021040141
#VU51858 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-10067
CWE-79 Low
No
No
- 22.05.2019 SB2019052233
SB2021040142
#VU17908 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2019-1543
CWE-327 Low
No
No
1.1.0k, 1.1.1c 06.03.2019 SB2019030602
SB2019040410
SB2019061209
and 13 more
#VU17860 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2019-1559
CWE-327 Low
No
No
1.0.2r 26.02.2019 SB2019022607
SB2019022802
SB2019022809
and 50 more
#VU15723 - Information Exposure Through Timing Discrepancy
CVE-2018-5407
CWE-208 Low
Available
No
1.1.0i 06.11.2018 SB2018110602
SB2018111301
SB2018112201
and 30 more
#VU15668 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0734
CWE-200 Low
No
No
1.0.2q, 1.1.0j, 1.1.1a 01.11.2018 SB2018110102
SB2018112201
SB2018112602
and 39 more
#VU15568 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0735
CWE-200 Low
No
No
1.1.0j, 1.1.1a 29.10.2018 SB2018110102
SB2018112602
SB2018112906
and 8 more
#VU13325 - Improper input validation
CVE-2018-0732
CWE-20 Low
No
No
1.0.2p, 1.1.0i 12.06.2018 SB2018061305
SB2018070906
SB2018073005
and 54 more
#VU11854 - Exposure of sensitive information to an unauthorized actor
CVE-2018-0737
CWE-200 Low
No
No
- 17.04.2018 SB2018041705
SB2018042001
SB2018070301
and 26 more
#VU11294 - Resource exhaustion
CVE-2018-0739
CWE-400 Low
No
No
- 28.03.2018 SB2018032804
SB2018032903
SB2018033002
and 35 more
#VU11293 - Improper Authentication
CVE-2018-0733
CWE-287 Low
No
No
- 28.03.2018 SB2018032804
SB2018071611
SB2018082403
and 5 more


Showing elements 121 - 140 out of 243