Libressl
Vendor:
First CVE: Dec 29, 2014 · Active for 11 years
12
Total CVEs
More Total CVEs than 90% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libressl over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 29, 2014
11 years ago
Most Recent CVE
Jun 16, 2023
1,135 days ago
CVE Severity & Scoring
Libressl12 CVEs
33%
42%
25%
All CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (33.3%)
Network7 (58.3%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (66.7%)
High3 (25.0%)
Unknown1 (8.3%)
User Interaction
None7 (58.3%)
Unknown1 (8.3%)
Required4 (33.3%)
Privileges Required
Low1 (8.3%)
High0 (0.0%)
None10 (83.3%)
Unknown1 (8.3%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-46880CRITICAL x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes disca | Apr 15, 2023 | 9.8 | 30 | NO | NO |
CVE-2015-5334CRITICAL Off-by-one error in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (program crash) or possible execute arbitrary code via a | Jan 23, 2020 | 9.8 | 27 | NO | NO |
CVE-2023-35784CRITICAL A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: O | Jun 16, 2023 | 9.8 | 24 | NO | NO |
CVE-2018-8970HIGH The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes si | Mar 24, 2018 | 7.4 | 24 | NO | NO |
CVE-2019-25049HIGH LibreSSL 2.9.1 through 3.2.1 has an out-of-bounds read in asn1_item_print_ctx (called from asn1_template_print_ctx). | Jul 1, 2021 | 7.1 | 22 | NO | NO |
CVE-2019-25048HIGH LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_item_print). | Jul 1, 2021 | 7.1 | 22 | NO | NO |
CVE-2015-5333HIGH Memory leak in the OBJ_obj2txt function in LibreSSL before 2.3.1 allows remote attackers to cause a denial of service (memory consumption) via a large number of ASN.1 object identi | Jan 23, 2020 | 7.5 | 22 | NO | NO |
CVE-2017-8301MEDIUM LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided v | Apr 27, 2017 | 5.3 | 21 | NO | NO |
CVE-2021-41581MEDIUM x509_constraints_parse_mailbox in lib/libcrypto/x509/x509_constraints.c in LibreSSL through 3.4.0 has a stack-based buffer over-read. When the input exceeds DOMAIN_PART_MAX_LEN, th | Sep 24, 2021 | 5.5 | 20 | NO | NO |
CVE-2014-9424HIGH Double free vulnerability in the ssl_parse_clienthello_use_srtp_ext function in d1_srtp.c in LibreSSL before 2.1.2 allows remote attackers to cause a denial of service or possibly | Dec 29, 2014 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Libressl
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.7.3 | 1 | 4.7 | 0.3% | 0 | 0 |
| 2.7.2 | 1 | 4.7 | 0.3% | 0 | 0 |
| 2.7.1 | 1 | 4.7 | 0.3% | 0 | 0 |
| 2.7.0 | 2 | 6.0 | 0.7% | 0 | 0 |
| 2.5.3 | 1 | 5.3 | 1.0% | 0 | 0 |
| 2.5.2 | 1 | 5.3 | 1.0% | 0 | 0 |
| 2.5.1 | 1 | 5.3 | 1.0% | 0 | 0 |