Openwall develops security-focused utilities and cryptographic libraries, with a niche but prominent footprint around password-hashing components such as crypt_blowfish and the OWL kernel hardening suite. The recurring signal centers on improper link-resolution and file-access issues reflective of the permission and path-handling demands of security tools operating at system privilege levels. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openwall over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2483MEDIUM crypt_blowfish before 1.1, as used in PHP before 5.3.7 on certain platforms, PostgreSQL before 8.4.9, and other products, does not properly handle 8-bit characters, which makes it | Aug 25, 2011 | 5.0 | 22 | NO | NO |
The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp func | Jun 30, 2011 | 3.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openwall.
Media articles that mention a CVE ID that affects a product developed by Openwall — matched by CVE ID, not by vendor name.