Exposición de OpenSSL

Web server extensions
518
score de exposición
64.416
sitios usan
0
en explotación
41
críticos
Análisis Vexday

Com 152 CVEs catalogadas e 35 surgidas nos últimos 90 dias, o OpenSSL apresenta um volume relevante de vulnerabilidades acumuladas, embora sua taxa de exploração ativa esteja abaixo da média geral do catálogo KEV — nenhuma de suas falhas consta atualmente no registro de vulnerabilidades exploradas pelo CISA. Ainda assim, o cenário exige atenção: o maior EPSS observado chega a 0,957, valor próximo ao limite máximo da escala, associado à CVE-2022-2068, o que indica altíssima probabilidade de exploração segundo os modelos preditivos. O tipo de falha mais comum é CWE-476 (desreferência de ponteiro nulo), que pode resultar em condições de negação de serviço em implementações que dependem da biblioteca. As 8 CVEs de severidade crítica reforçam a necessidade de ciclos de atualização rigorosos em qualquer ambiente que utilize OpenSSL como componente de infraestrutura criptográfica.

CVEs

233 resultados
CVE-2025-69419HIGHOut of bounds write in PKCS12_get_friendlyname() UTF-8 conversionEPSS 0.6%CVE-2026-42767MEDIUMNULL Pointer Dereference in CRMF EncryptedValue DecryptionEPSS 0.6%CVE-2026-54874HIGHExcessive Memory Use Buffering DTLS Records for a Future EpochEPSS 0.5%CVE-2026-22796MEDIUMASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() functionEPSS 0.5%CVE-2024-31074HIGHObservable timing discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via neEPSS 0.5%CVE-2024-2467MEDIUMPerl-crypt-openssl-rsa: side-channel attack in pkcs#1 v1.5 padding mode (marvin attack)EPSS 0.5%CVE-2026-42765HIGHNULL Dereference in Certificate Verification with OCSP CheckingEPSS 0.5%CVE-2025-3416LOWRust-openssl: rust-openssl use-after-free in `md::fetch` and `cipher::fetch`EPSS 0.5%CVE-2026-42770LOWFFC-DH Peer Validation Uses Attacker-Supplied qEPSS 0.5%CVE-2026-63074MEDIUMCMP Indefinite Cache Growth of ExtraCertsEPSS 0.5%CVE-2026-74899CRITICALopenssl_encrypt before 1.4.0 Sandbox Escape via Type HierarchyEPSS 0.5%CVE-2026-81690HIGHverify-usb before 1.4.9 Symlink Directory Traversal Code ExecutionEPSS 0.5%CVE-2026-63075HIGHQUIC ACK-only Packet Retention Can Cause Memory ExhaustionEPSS 0.5%CVE-2026-74872CRITICALopenssl_encrypt before 1.4.0 Arbitrary Code Execution via WhirlpoolEPSS 0.5%CVE-2024-33617HIGHInsufficient control flow management in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosureEPSS 0.5%CVE-2026-8721CRITICALCrypt::OpenSSL::PKCS12 versions through 1.94 for Perl truncates passwords with embedded NULLsEPSS 0.4%CVE-2026-17510HIGHCrypt::OpenSSL::PKCS12 versions before 1.98 for Perl allow a NULL pointer dereference in print_attribute via a zero length BMPSTRING attributeEPSS 0.4%CVE-2026-45446MEDIUMIncorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modesEPSS 0.4%CVE-2026-2673MEDIUMOpenSSL TLS 1.3 server may choose unexpected key agreement groupEPSS 0.4%CVE-2024-28885HIGHObservable discrepancy in some Intel(R) QAT Engine for OpenSSL software before version v1.6.1 may allow information disclosure via network aEPSS 0.4%