Vulnerabilidades em OpenSSL

128 resultados
Análise Vexday

Com 117 CVEs catalogadas e nenhuma entrada no catálogo KEV da CISA, o OpenSSL apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que não elimina a necessidade de atenção — especialmente considerando que 25 vulnerabilidades surgiram nos últimos 90 dias e 5 possuem PoC pública disponível. O tipo de falha mais comum é CWE-476 (desreferência de ponteiro nulo), padrão recorrente em bibliotecas criptográficas de baixo nível que pode resultar em condições de negação de serviço. A CVE mais crítica em destaque, CVE-2022-2068, registra EPSS de 0,9576 — valor altamente elevado que indica forte probabilidade estatística de exploração —, sendo recomendada sua priorização imediata em qualquer inventário que utilize versões afetadas da biblioteca.

CVE-2019-1543ChaCha20-Poly1305 with long noncesEPSS 5.4%CVE-2022-2097AES OCB fails to encrypt some bytesEPSS 4.9%CVE-2020-1968LOWRaccoon attackEPSS 4.8%CVE-2018-0735Timing attack against ECDSA signature generationEPSS 4.8%CVE-2025-11187MEDIUMImproper validation of PBMAC1 parameters in PKCS#12 MAC verificationEPSS 4.7%CVE-2023-0215HIGHUse-after-free following BIO_new_NDEFEPSS 4.5%CVE-2023-5678MEDIUMExcessive time spent in DH check / generation with large Q parameter valueEPSS 4.5%CVE-2019-1563Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkeyEPSS 3.8%CVE-2021-4160BN_mod_exp may produce incorrect results on MIPSEPSS 3.8%CVE-2023-0464HIGHExcessive Resource Usage Verifying X.509 Policy ConstraintsEPSS 3.7%CVE-2026-45447HIGHHeap Use-After-Free in the PKCS7_verify() FunctionEPSS 3.6%CVE-2023-5363HIGHIncorrect cipher key & IV length processingEPSS 3.3%CVE-2024-0727MEDIUMPKCS12 Decoding crashesEPSS 3.2%CVE-2022-3358Using a Custom Cipher with NID_undef may lead to NULL encryptionEPSS 3.1%CVE-2023-3817MEDIUMExcessive time spent checking DH q parameter valueEPSS 3.0%CVE-2021-23839Incorrect SSLv2 rollback protectionEPSS 3.0%CVE-2024-4741HIGHUse After Free with SSL_free_buffersEPSS 2.9%CVE-2024-12797MEDIUMRFC7250 handshakes with unauthenticated servers don't abort as expectedEPSS 2.5%CVE-2011-4121The OpenSSL extension of Ruby (Git trunk) versions after 2011-09-01 up to 2011-11-03 always generated an exponent value of '1' to be used foEPSS 2.5%CVE-2022-1473HIGHResource leakage when decoding certificates and keysEPSS 2.5%