Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenSSL — Vulnerabilities & Security Advisories 142

Browse all 142 CVE security advisories affecting OpenSSL. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenSSL is an open-source toolkit implementing the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, primarily used to encrypt network traffic for web servers, email systems, and other internet services. Its widespread adoption makes it a critical infrastructure component, yet its complexity has historically led to numerous vulnerabilities. Common flaw classes include buffer overflows, memory corruption issues, and logic errors that can facilitate remote code execution or denial of service attacks. Notable incidents, such as the Heartbleed bug, exposed sensitive memory data, highlighting risks associated with complex cryptographic implementations. With approximately 99 recorded CVEs, the project emphasizes rigorous code auditing and timely patching to mitigate these risks. Developers must maintain strict version control and apply updates promptly to ensure secure communications, as unpatched instances remain vulnerable to exploitation by malicious actors seeking to intercept or manipulate data in transit.

CVE ID Title CVSS Severity Published
CVE-2022-4304 Timing Oracle in RSA Decryption — OpenSSL 5.9 - 2023-02-08
CVE-2022-4450 Double free after calling PEM_read_bio_ex — OpenSSL 7.5 - 2023-02-08
CVE-2023-0215 Use-after-free following BIO_new_NDEF — OpenSSL 9.1 - 2023-02-08
CVE-2023-0216 Invalid pointer dereference in d2i_PKCS7 functions — OpenSSL 7.5 - 2023-02-08
CVE-2023-0217 NULL dereference validating DSA public key — OpenSSL 7.5 - 2023-02-08
CVE-2023-0286 X.400 address type confusion in X.509 GeneralName — OpenSSL 9.1 - 2023-02-08
CVE-2023-0401 NULL dereference during PKCS7 data verification — OpenSSL 7.5 - 2023-02-08
CVE-2022-3996 X.509 Policy Constraints Double Locking — OpenSSL CWE-667 7.5 - 2022-12-13
CVE-2022-3602 X.509 Email Address 4-byte Buffer Overflow — OpenSSL 9.1 - 2022-11-01
CVE-2022-3786 X.509 Email Address Variable Length Buffer Overflow — OpenSSL 7.5 - 2022-11-01
CVE-2022-3358 Using a Custom Cipher with NID_undef may lead to NULL encryption — OpenSSL 7.5 - 2022-10-11
CVE-2022-2097 AES OCB fails to encrypt some bytes — OpenSSL 5.3 - 2022-07-05
CVE-2022-2274 RSA implementation bug in AVX512IFMA instructions — OpenSSL 9.8 - 2022-07-01
CVE-2022-2068 The c_rehash script allows command injection — OpenSSL 9.8 - 2022-06-21
CVE-2022-1473 Resource leakage when decoding certificates and keys — OpenSSL 7.5 - 2022-05-03
CVE-2022-1434 Incorrect MAC key used in the RC4-MD5 ciphersuite — OpenSSL 5.9 - 2022-05-03
CVE-2022-1343 OCSP_basic_verify may incorrectly verify the response signing certificate — OpenSSL 9.1 - 2022-05-03
CVE-2022-1292 The c_rehash script allows command injection — OpenSSL 9.8 - 2022-05-03
CVE-2022-0778 Infinite loop in BN_mod_sqrt() reachable when parsing certificates — OpenSSL 7.5 - 2022-03-15
CVE-2021-4160 BN_mod_exp may produce incorrect results on MIPS — OpenSSL 5.9 - 2022-01-28
CVE-2021-4044 Invalid handling of X509_verify_cert() internal errors in libssl — OpenSSL 7.5 - 2021-12-14
CVE-2021-3712 Read buffer overruns processing ASN.1 strings — OpenSSL 7.4 - 2021-08-24
CVE-2021-3711 SM2 Decryption Buffer Overflow — OpenSSL 9.8 - 2021-08-24
CVE-2021-3449 NULL pointer deref in signature_algorithms processing — OpenSSL 5.9 - 2021-03-25
CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICT — OpenSSL 9.1 - 2021-03-25
CVE-2021-23841 Null pointer deref in X509_issuer_and_serial_hash() — OpenSSL 5.9 - 2021-02-16
CVE-2021-23839 Incorrect SSLv2 rollback protection — OpenSSL 7.5 - 2021-02-16
CVE-2021-23840 Integer overflow in CipherUpdate — OpenSSL 7.5 - 2021-02-16
CVE-2020-1971 EDIPARTYNAME NULL pointer dereference — OpenSSL 5.9 - 2020-12-08
CVE-2020-1968 Raccoon attack — OpenSSL 5.9 - 2020-09-09

This page lists every published CVE security advisory associated with OpenSSL. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.