OpenSSL Software Foundation

First CVE: May 4, 2017Active for: 9 years
119
CVEs Published
More CVEs Published than 72% of tracked CNAs
11.9
Avg CVEs / Year
More Avg CVEs / Year than 58% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 26% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by OpenSSL Software Foundation as a CNA, 100.0% affect products that OpenSSL Software Foundation develops as a vendor.

100.0%
Self-reported: 119Third-party: 0

Of all the CVEs published that affect products developed by OpenSSL Software Foundation, 38.9% are self-published by OpenSSL Software Foundation as a CNA.

38.9%
61.1%
Self-published: 119Published by other CNAs: 187

Trends Over Time

The number and severity of CVEs published by OpenSSL Software Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 4, 2017
9 years ago
Most Recent CVE
Jun 9, 2026
45 days ago

Top CVEs

All CVEs published by OpenSSL Software Foundation as a CNA, regardless of affected vendor or product.

119 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim
Aug 24, 20219.879NONO
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification
Nov 1, 20227.576NONO
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to
Jun 21, 20227.376NONO
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification
Nov 1, 20227.575NONO
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is autom
May 3, 20227.368NONO
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer
Jan 27, 20269.867NONO
In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL po
May 4, 20177.567NOYES
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsi
Mar 15, 20227.565NONO
OpenSSL 1.0.2 (starting from version 1.0.2b) introduced an "error state" mechanism. The intent was that if a fatal error occurred during a handshake then OpenSSL would move into th
Dec 7, 20175.965NONO
Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, o
May 30, 20236.564NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA119 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local12 (10.1%)
Network106 (89.1%)
Unknown0 (0.0%)
Physical1 (0.8%)
Adjacent Network0 (0.0%)
Attack Complexity
Low77 (64.7%)
High42 (35.3%)
Unknown0 (0.0%)
User Interaction
None111 (93.3%)
Unknown0 (0.0%)
Required8 (6.7%)
Privileges Required
Low13 (10.9%)
High1 (0.8%)
None105 (88.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (119 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.8% of CVEs· 86th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.7% of CVEs· 86th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by OpenSSL Software Foundation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by OpenSSL Software Foundation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs