The OpenSSL Software Foundation maintains a cryptographic library that, despite a minimal product roster, occupies a critical position in the global software supply chain and is embedded across an enormous range of servers, appliances, and applications. The vendor's exposure is heavily represented in the vulnerability landscape precisely because a single flaw can propagate to every downstream product that links the library, amplifying the practical impact of each disclosure. Vulnerabilities skew toward serious outcomes, particularly within the core OpenSSL and FIPS Object Module products, and recur through weakness classes including NULL-pointer dereferences, certificate validation bypasses, memory-buffer violations, and information-exposure conditions that reflect the parsing complexity and cryptographic-state management inherent to a TLS and general-purpose crypto implementation. Many OpenSSL vulnerabilities acquire public exploit tooling, underscoring the appeal of the library as a target for attackers seeking to compromise downstream systems at scale. Defenders should inventory and prioritize remediation of products that bundle this library rather than tracking the library alone, as exposure depends heavily on which downstream vendors and deployment contexts have integrated and updated it; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by OpenSSL Software Foundation over time
Of all the CVEs published by OpenSSL Software Foundation as a CNA, 100.0% affect products that OpenSSL Software Foundation develops as a vendor.
Of all the CVEs published that affect products developed by OpenSSL Software Foundation, 38.9% are self-published by OpenSSL Software Foundation as a CNA.
Signals from CVEs in this vendor scope (306 CVEs).
306 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-0160HIGH The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive inform | Apr 7, 2014 | 7.5 | 99 | YES | YES |
CVE-2009-3555CRITICAL The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, | Nov 9, 2009 | 9.8 | 85 | NO | YES |
CVE-2014-0224HIGH OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to | Jun 5, 2014 | 7.4 | 83 | NO | YES |
CVE-2002-0656HIGH Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a lar | Aug 12, 2002 | 7.5 | 81 | NO | YES |
CVE-2014-0195MEDIUM The dtls1_reassemble_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly validate fragment lengths in DTLS Clie | Jun 5, 2014 | 6.8 | 80 | NO | YES |
CVE-2021-3711CRITICAL In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first tim | Aug 24, 2021 | 9.8 | 79 | NO | NO |
CVE-2016-2107MEDIUM The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obta | May 5, 2016 | 5.9 | 79 | NO | YES |
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain clear | Oct 15, 2014 | 3.4 | 78 | NO | YES |
CVE-2016-2183HIGH The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak | Sep 1, 2016 | 7.5 | 77 | NO | NO |
CVE-2009-1386MEDIUM ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a DTLS ChangeCipherSpec packet that occur | Jun 4, 2009 | 5.0 | 77 | NO | YES |
Signals from CVEs in this vendor scope (306 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by OpenSSL Software Foundation.
Media articles that mention a CVE ID that affects a product developed by OpenSSL Software Foundation — matched by CVE ID, not by vendor name.