Io Socket Ssl is a narrowly scoped Perl socket library that provides SSL/TLS encryption support, representing a niche component deployed in systems that rely on Perl for network communication. The vendor's reported vulnerability exposure is small and centered on this single library product, with no distinctive weakness class pattern emerging from the available disclosures. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Io Socket Ssl over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4334MEDIUM The IO::Socket::SSL module 1.35 for Perl, when verify_mode is not VERIFY_NONE, fails open to VERIFY_NONE instead of throwing an error when a ca_file/ca_path cannot be verified, whi | Jan 14, 2011 | 4.0 | 17 | NO | NO |
CVE-2009-3024MEDIUM The verify_hostname_of_cert function in the certificate checking feature in IO-Socket-SSL (IO::Socket::SSL) 1.14 through 1.25 only matches the prefix of a hostname when no wildcard | Aug 31, 2009 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Io Socket Ssl.
Media articles that mention a CVE ID that affects a product developed by Io Socket Ssl — matched by CVE ID, not by vendor name.