Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenSSL — Vulnerabilities & Security Advisories 142

Browse all 142 CVE security advisories affecting OpenSSL. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenSSL is an open-source toolkit implementing the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, primarily used to encrypt network traffic for web servers, email systems, and other internet services. Its widespread adoption makes it a critical infrastructure component, yet its complexity has historically led to numerous vulnerabilities. Common flaw classes include buffer overflows, memory corruption issues, and logic errors that can facilitate remote code execution or denial of service attacks. Notable incidents, such as the Heartbleed bug, exposed sensitive memory data, highlighting risks associated with complex cryptographic implementations. With approximately 99 recorded CVEs, the project emphasizes rigorous code auditing and timely patching to mitigate these risks. Developers must maintain strict version control and apply updates promptly to ensure secure communications, as unpatched instances remain vulnerable to exploitation by malicious actors seeking to intercept or manipulate data in transit.

CVE ID Title CVSS Severity Published
CVE-2025-15468 NULL dereference in SSL_CIPHER_find() function on unknown cipher ID — OpenSSL CWE-476 7.5AI High AI 2026-01-27
CVE-2025-15467 Stack buffer overflow in CMS (Auth)EnvelopedData parsing — OpenSSL CWE-787 9.8 - 2026-01-27
CVE-2025-11187 Improper validation of PBMAC1 parameters in PKCS#12 MAC verification — OpenSSL CWE-787 8.8AI High AI 2026-01-27
CVE-2025-9232 Out-of-bounds read in HTTP client no_proxy handling — OpenSSL CWE-125 7.5AI High AI 2025-09-30
CVE-2025-9231 Timing side-channel in SM2 algorithm on 64 bit ARM — OpenSSL CWE-385 5.9AI Medium AI 2025-09-30
CVE-2025-9230 Out-of-bounds read & write in RFC 3211 KEK Unwrap — OpenSSL CWE-125 9.1AI Critical AI 2025-09-30
CVE-2025-4575 The x509 application adds trusted use instead of rejected use — OpenSSL CWE-295 7.5AI High AI 2025-05-22
CVE-2024-12797 RFC7250 handshakes with unauthenticated servers don't abort as expected — OpenSSL CWE-392 7.4 - 2025-02-11
CVE-2024-13176 Timing side-channel in ECDSA signature computation — OpenSSL CWE-385 4.7 - 2025-01-20
CVE-2024-4741 Use After Free with SSL_free_buffers — OpenSSL CWE-416 9.8 - 2024-11-13
CVE-2024-9143 Low-level invalid GF(2^m) parameters lead to OOB memory access — OpenSSL CWE-125 9.8 - 2024-10-16
CVE-2024-6119 Possible denial of service in X.509 name checks — OpenSSL CWE-843 7.5AI High AI 2024-09-03
CVE-2024-5535 SSL_select_next_proto buffer overread — OpenSSL CWE-125 9.1AI Critical AI 2024-06-27
CVE-2024-4603 Excessive time spent checking DSA keys and parameters — OpenSSL CWE-606 7.5AI High AI 2024-05-16
CVE-2023-6237 Excessive time spent checking invalid RSA public keys — OpenSSL CWE-606 7.5 - 2024-04-25
CVE-2024-2511 Unbounded memory growth with session handling in TLSv1.3 — OpenSSL CWE-1325 7.5AI High AI 2024-04-08
CVE-2024-0727 PKCS12 Decoding crashes — OpenSSL CWE-476 6.5 - 2024-01-26
CVE-2023-6129 POLY1305 MAC implementation corrupts vector registers on PowerPC — OpenSSL CWE-440 9.8AI Critical AI 2024-01-09
CVE-2023-5678 Excessive time spent in DH check / generation with large Q parameter value — OpenSSL CWE-606 5.3 - 2023-11-06
CVE-2023-5363 Incorrect cipher key & IV length processing — OpenSSL CWE-684 5.3 - 2023-10-24
CVE-2023-4807 POLY1305 MAC implementation corrupts XMM registers on Windows — OpenSSL CWE-440 9.8 - 2023-09-08
CVE-2023-3817 Excessive time spent checking DH q parameter value — OpenSSL CWE-606 7.5 - 2023-07-31
CVE-2023-3446 Excessive time spent checking DH keys and parameters — OpenSSL CWE-606 7.5 - 2023-07-19
CVE-2023-2975 AES-SIV implementation ignores empty associated data entries — OpenSSL CWE-354 7.5 - 2023-07-14
CVE-2023-2650 Possible DoS translating ASN.1 object identifiers — OpenSSL 7.5 - 2023-05-30
CVE-2023-1255 Input buffer over-read in AES-XTS implementation on 64 bit ARM — OpenSSL 7.5 - 2023-04-20
CVE-2023-0466 Certificate policy check not enabled — OpenSSL 5.3 - 2023-03-28
CVE-2023-0465 Invalid certificate policies in leaf certificates are silently ignored — OpenSSL 6.5 - 2023-03-28
CVE-2023-0464 Excessive Resource Usage Verifying X.509 Policy Constraints — OpenSSL 7.5 - 2023-03-22
CVE-2022-4203 X.509 Name Constraints Read Buffer Overflow — OpenSSL 4.9 - 2023-02-24

This page lists every published CVE security advisory associated with OpenSSL. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.