Vulnerabilidades en OpenSSL

128 resultados
Análisis Vexday

Com 117 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o OpenSSL apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que não elimina a necessidade de atenção — especialmente considerando que 25 vulnerabilidades surgiram nos últimos 90 dias e 5 possuem PoC pública disponível. O tipo de falha mais comum é CWE-476 (desreferência de ponteiro nulo), padrão recorrente em bibliotecas criptográficas de baixo nível que pode resultar em condições de negação de serviço. A CVE mais crítica em destaque, CVE-2022-2068, registra EPSS de 0,9576 — valor altamente elevado que indica forte probabilidade estatística de exploração —, sendo recomendada sua priorização imediata em qualquer inventário que utilize versões afetadas da biblioteca.

CVE-2026-34183HIGHUnbounded Memory Growth in the QUIC PATH_CHALLENGE HandlerEPSS 1.0%CVE-2026-31790HIGHIncorrect Failure Handling in RSA KEM RSASVE EncapsulationEPSS 1.0%CVE-2026-34180HIGHHeap Buffer Over-read in ASN.1 Content ParsingEPSS 1.0%CVE-2026-14457HIGHRPK Server Signature Algorithm Selection Can Dereference a Missing CertificateEPSS 1.0%CVE-2023-1255MEDIUMInput buffer over-read in AES-XTS implementation on 64 bit ARMEPSS 1.0%CVE-2026-63073CRITICALUntrusted Sender DN Used as Format String in CMP Response ValidationEPSS 0.9%CVE-2025-69421HIGHNULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex functionEPSS 0.9%CVE-2026-28388HIGHNULL Pointer Dereference When Processing a Delta CRLEPSS 0.9%CVE-2023-4807HIGHPOLY1305 MAC implementation corrupts XMM registers on WindowsEPSS 0.8%CVE-2025-69420HIGHMissing ASN1_TYPE validation in TS_RESP_verify_response() functionEPSS 0.8%CVE-2026-28389HIGHPossible NULL Dereference When Processing CMS KeyAgreeRecipientInfoEPSS 0.8%CVE-2026-28390HIGHPossible NULL Dereference When Processing CMS KeyTransportRecipientInfoEPSS 0.8%CVE-2026-7383HIGHPossible Heap Buffer Overflow in ASN.1 Multibyte String ConversionEPSS 0.8%CVE-2025-15468MEDIUMNULL dereference in SSL_CIPHER_find() function on unknown cipher IDEPSS 0.8%CVE-2026-14456HIGHUnbounded Memory Growth in QUIC Server Incoming Channel QueueEPSS 0.7%CVE-2026-9076HIGHOut-of-Bounds Read in CMS Password-Based DecryptionEPSS 0.7%CVE-2026-45445HIGHAES-OCB IV Ignored on EVP_Cipher() PathEPSS 0.7%CVE-2019-1552Windows builds with insecure path defaultsEPSS 0.7%CVE-2026-63072HIGHHeap Buffer Overflow in CMS Key UnwrappingEPSS 0.7%CVE-2026-28387HIGHPotential Use-after-free in DANE Client CodeEPSS 0.7%