Vulnerabilidades en OpenSSL

128 resultados
Análisis Vexday

Com 117 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o OpenSSL apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que não elimina a necessidade de atenção — especialmente considerando que 25 vulnerabilidades surgiram nos últimos 90 dias e 5 possuem PoC pública disponível. O tipo de falha mais comum é CWE-476 (desreferência de ponteiro nulo), padrão recorrente em bibliotecas criptográficas de baixo nível que pode resultar em condições de negação de serviço. A CVE mais crítica em destaque, CVE-2022-2068, registra EPSS de 0,9576 — valor altamente elevado que indica forte probabilidade estatística de exploração —, sendo recomendada sua priorização imediata em qualquer inventário que utilize versões afetadas da biblioteca.

CVE-2023-6129MEDIUMPOLY1305 MAC implementation corrupts vector registers on PowerPCEPSS 2.3%CVE-2023-6237MEDIUMExcessive time spent checking invalid RSA public keysEPSS 2.3%CVE-2025-9231MEDIUMTiming side-channel in SM2 algorithm on 64 bit ARMEPSS 2.2%CVE-2025-9232MEDIUMOut-of-bounds read in HTTP client no_proxy handlingEPSS 2.0%CVE-2023-0216HIGHInvalid pointer dereference in d2i_PKCS7 functionsEPSS 1.8%CVE-2023-0401HIGHNULL dereference during PKCS7 data verificationEPSS 1.8%CVE-2023-0217HIGHNULL dereference validating DSA public keyEPSS 1.8%CVE-2023-0466MEDIUMCertificate policy check not enabledEPSS 1.6%CVE-2023-0465MEDIUMInvalid certificate policies in leaf certificates are silently ignoredEPSS 1.6%CVE-2025-9230HIGHOut-of-bounds read & write in RFC 3211 KEK UnwrapEPSS 1.6%CVE-2026-18798HIGHQUIC Server May Trigger Double Free When Processing INITIAL PacketEPSS 1.5%CVE-2022-4203MEDIUMX.509 Name Constraints Read Buffer OverflowEPSS 1.4%CVE-2026-63076HIGHInvalid Pointer Dereference in CMP Server via Crafted protectionAlgEPSS 1.4%CVE-2022-3996HIGHX.509 Policy Constraints Double LockingEPSS 1.2%CVE-2022-1343MEDIUMOCSP_basic_verify may incorrectly verify the response signing certificateEPSS 1.2%CVE-2019-1547ECDSA remote timing attackEPSS 1.2%CVE-2026-42764HIGHNULL Pointer Dereference in QUIC Server Initial Packet HandlingEPSS 1.2%CVE-2024-4603MEDIUMExcessive time spent checking DSA keys and parametersEPSS 1.1%CVE-2022-1434Incorrect MAC key used in the RC4-MD5 ciphersuiteEPSS 1.1%CVE-2026-42766MEDIUMPossible NULL Dereference in Password-Based CMS DecryptionEPSS 1.1%