vciy

CVEs we hold for Openssl

Records whose assigning authority named Openssl as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9076Out-of-Bounds Read in CMS Password-Based DecryptionOpenSSL
CVE-2026-75803AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()OpenSSL
CVE-2026-7383Possible Heap Buffer Overflow in ASN.1 Multibyte String ConversionOpenSSL
CVE-2026-63076Invalid Pointer Dereference in CMP Server via Crafted protectionAlgOpenSSL
CVE-2026-63075QUIC ACK-only Packet Retention Can Cause Memory ExhaustionOpenSSL
CVE-2026-63074CMP Indefinite Cache Growth of ExtraCertsOpenSSL
CVE-2026-63073Untrusted Sender DN Used as Format String in CMP Response ValidationOpenSSL
CVE-2026-63072Heap Buffer Overflow in CMS Key UnwrappingOpenSSL
CVE-2026-54876Client-Side Memory Leak in OCSP Response CheckingOpenSSL
CVE-2026-54874Excessive Memory Use Buffering DTLS Records for a Future EpochOpenSSL
CVE-2026-45447Heap Use-After-Free in the PKCS7_verify() FunctionOpenSSL
CVE-2026-45446Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modesOpenSSL
CVE-2026-45445AES-OCB IV Ignored on EVP_Cipher() PathOpenSSL
CVE-2026-42771Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email()OpenSSL
CVE-2026-42770FFC-DH Peer Validation Uses Attacker-Supplied qOpenSSL
CVE-2026-42769Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdateOpenSSL
CVE-2026-42768Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()OpenSSL
CVE-2026-42767NULL Pointer Dereference in CRMF EncryptedValue DecryptionOpenSSL
CVE-2026-42766Possible NULL Dereference in Password-Based CMS DecryptionOpenSSL
CVE-2026-42765NULL Dereference in Certificate Verification with OCSP CheckingOpenSSL
CVE-2026-42764NULL Pointer Dereference in QUIC Server Initial Packet HandlingOpenSSL
CVE-2026-35188Double-free When Checking OCSP Stapled ResponseOpenSSL
CVE-2026-34183Unbounded Memory Growth in the QUIC PATH_CHALLENGE HandlerOpenSSL
CVE-2026-34182CMS AuthEnvelopedData Processing May Accept Forged MessagesOpenSSL
CVE-2026-34181PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC KeysOpenSSL
CVE-2026-34180Heap Buffer Over-read in ASN.1 Content ParsingOpenSSL
CVE-2026-31790Incorrect Failure Handling in RSA KEM RSASVE EncapsulationOpenSSL
CVE-2026-31789Heap Buffer Overflow in Hexadecimal ConversionOpenSSL
CVE-2026-28390Possible NULL Dereference When Processing CMS KeyTransportRecipientInfoOpenSSL
CVE-2026-28389Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfoOpenSSL
CVE-2026-28388NULL Pointer Dereference When Processing a Delta CRLOpenSSL
CVE-2026-28387Potential Use-after-free in DANE Client CodeOpenSSL
CVE-2026-28386Out-of-bounds Read in AES-CFB-128 on X86-64 with AVX-512 SupportOpenSSL
CVE-2026-2673OpenSSL TLS 1.3 server may choose unexpected key agreement groupOpenSSL
CVE-2026-22796ASN1_TYPE Type Confusion in the PKCS7_digest_from_attributes() functionOpenSSL
CVE-2026-22795Missing ASN1_TYPE validation in PKCS#12 parsingOpenSSL
CVE-2026-18798QUIC Server May Trigger Double Free When Processing INITIAL PacketOpenSSL
CVE-2026-14457RPK Server Signature Algorithm Selection Can Dereference a Missing CertificateOpenSSL
CVE-2026-14456Unbounded Memory Growth in QUIC Server Incoming Channel QueueOpenSSL
CVE-2025-9232Out-of-bounds read in HTTP client no_proxy handlingOpenSSL
CVE-2025-9231Timing side-channel in SM2 algorithm on 64 bit ARMOpenSSL
CVE-2025-9230Out-of-bounds read & write in RFC 3211 KEK UnwrapOpenSSL
CVE-2025-69421NULL Pointer Dereference in PKCS12_item_decrypt_d2i_ex functionOpenSSL
CVE-2025-69420Missing ASN1_TYPE validation in TS_RESP_verify_response() functionOpenSSL
CVE-2025-69419Out of bounds write in PKCS12_get_friendlyname() UTF-8 conversionOpenSSL
CVE-2025-69418Unauthenticated/unencrypted trailing bytes with low-level OCB function callsOpenSSL
CVE-2025-68160Heap out-of-bounds write in BIO_f_linebuffer on short writesOpenSSL
CVE-2025-66199TLS 1.3 CompressedCertificate excessive memory allocationOpenSSL
CVE-2025-4575The x509 application adds trusted use instead of rejected useOpenSSL
CVE-2025-15469'openssl dgst' one-shot codepath silently truncates inputs >16MBOpenSSL
CVE-2025-15468NULL dereference in SSL_CIPHER_find() function on unknown cipher IDOpenSSL
CVE-2025-15467Stack buffer overflow in CMS (Auth)EnvelopedData parsingOpenSSL
CVE-2025-11187Improper validation of PBMAC1 parameters in PKCS#12 MAC verificationOpenSSL
CVE-2024-9143Low-level invalid GF(2^m) parameters lead to OOB memory accessOpenSSL
CVE-2024-6119Possible denial of service in X.509 name checksOpenSSL
CVE-2024-5535SSL_select_next_proto buffer overreadOpenSSL
CVE-2024-4741Use After Free with SSL_free_buffersOpenSSL
CVE-2024-4603Excessive time spent checking DSA keys and parametersOpenSSL
CVE-2024-2511Unbounded memory growth with session handling in TLSv1.3OpenSSL
CVE-2024-13176Timing side-channel in ECDSA signature computationOpenSSL
CVE-2024-12797RFC7250 handshakes with unauthenticated servers don't abort as expectedOpenSSL
CVE-2024-0727PKCS12 Decoding crashesOpenSSL
CVE-2023-6237Excessive time spent checking invalid RSA public keysOpenSSL
CVE-2023-6129POLY1305 MAC implementation corrupts vector registers on PowerPCOpenSSL
CVE-2023-5678Excessive time spent in DH check / generation with large Q parameter valueOpenSSL
CVE-2023-5363Incorrect cipher key & IV length processingOpenSSL
CVE-2023-4807POLY1305 MAC implementation corrupts XMM registers on WindowsOpenSSL
CVE-2023-3817Excessive time spent checking DH q parameter valueOpenSSL
CVE-2023-3446Excessive time spent checking DH keys and parametersOpenSSL
CVE-2023-2975AES-SIV implementation ignores empty associated data entriesOpenSSL
CVE-2023-2650Possible DoS translating ASN.1 object identifiersOpenSSL
CVE-2023-1255Input buffer over-read in AES-XTS implementation on 64 bit ARMOpenSSL
CVE-2023-0466Certificate policy check not enabledOpenSSL
CVE-2023-0465Invalid certificate policies in leaf certificates are silently ignoredOpenSSL
CVE-2023-0464Excessive Resource Usage Verifying X.509 Policy ConstraintsOpenSSL
CVE-2023-0401NULL dereference during PKCS7 data verificationOpenSSL
CVE-2023-0286X.400 address type confusion in X.509 GeneralNameOpenSSL
CVE-2023-0217NULL dereference validating DSA public keyOpenSSL
CVE-2023-0216Invalid pointer dereference in d2i_PKCS7 functionsOpenSSL
CVE-2023-0215Use-after-free following BIO_new_NDEFOpenSSL
CVE-2022-4450Double free after calling PEM_read_bio_exOpenSSL
CVE-2022-4304Timing Oracle in RSA DecryptionOpenSSL
CVE-2022-4203X.509 Name Constraints Read Buffer OverflowOpenSSL
CVE-2022-3996X.509 Policy Constraints Double LockingOpenSSL
CVE-2022-3786X.509 Email Address Variable Length Buffer OverflowOpenSSL
CVE-2022-3602X.509 Email Address 4-byte Buffer OverflowOpenSSL
CVE-2022-3358Using a Custom Cipher with NID_undef may lead to NULL encryptionOpenSSL
CVE-2022-2274RSA implementation bug in AVX512IFMA instructionsOpenSSL
CVE-2022-2097AES OCB fails to encrypt some bytesOpenSSL
CVE-2022-2068The c_rehash script allows command injectionOpenSSL
CVE-2022-1473Resource leakage when decoding certificates and keysOpenSSL
CVE-2022-1434Incorrect MAC key used in the RC4-MD5 ciphersuiteOpenSSL
CVE-2022-1343OCSP_basic_verify may incorrectly verify the response signing certificateOpenSSL
CVE-2022-1292The c_rehash script allows command injectionOpenSSL
CVE-2022-0778Infinite loop in BN_mod_sqrt() reachable when parsing certificatesOpenSSL
CVE-2021-4160BN_mod_exp may produce incorrect results on MIPSOpenSSL
CVE-2021-4044Invalid handling of X509_verify_cert() internal errors in libsslOpenSSL
CVE-2021-3712Read buffer overruns processing ASN.1 stringsOpenSSL
CVE-2021-3711SM2 Decryption Buffer OverflowOpenSSL
CVE-2021-3450CA certificate check bypass with X509_V_FLAG_X509_STRICTOpenSSL
CVE-2021-3449NULL pointer deref in signature_algorithms processingOpenSSL
CVE-2021-23841Null pointer deref in X509_issuer_and_serial_hash()OpenSSL
CVE-2021-23840Integer overflow in CipherUpdateOpenSSL
CVE-2021-23839Incorrect SSLv2 rollback protectionOpenSSL
CVE-2020-1971EDIPARTYNAME NULL pointer dereferenceOpenSSL
CVE-2020-1968Raccoon attackOpenSSL
CVE-2020-1967Segmentation fault in SSL_check_chainOpenSSL
CVE-2019-1563Padding Oracle in PKCS7_dataDecode and CMS_decrypt_set1_pkeyOpenSSL
CVE-2019-15590-byte record padding oracleOpenSSL
CVE-2019-1552Windows builds with insecure path defaultsOpenSSL
CVE-2019-1551rsaz_512_sqr overflow bug on x86_64OpenSSL
CVE-2019-1549Fork ProtectionOpenSSL
CVE-2019-1547ECDSA remote timing attackOpenSSL
CVE-2019-1543ChaCha20-Poly1305 with long noncesOpenSSL
CVE-2018-0739Constructed ASN.1 types with a recursive definition could exceed the stackOpenSSL
CVE-2018-0737Cache timing vulnerability in RSA Key GenerationOpenSSL
CVE-2018-0735Timing attack against ECDSA signature generationOpenSSL
CVE-2018-0734Timing attack against DSAOpenSSL
CVE-2018-0733Incorrect CRYPTO_memcmp on HP-UX PA-RISCOpenSSL
CVE-2018-0732Client DoS due to large DH parameterOpenSSL
CVE-2017-3738no title heldOpenSSL
CVE-2017-3737no title heldOpenSSL
CVE-2017-3736no title heldOpenSSL
CVE-2017-3735no title heldOpenSSL
CVE-2017-3733Encrypt-Then-Mac renegotiation crashOpenSSL
CVE-2017-3732BN_mod_exp may produce incorrect results on x86_64OpenSSL
CVE-2017-3731Truncated packet could crash via OOB readOpenSSL
CVE-2017-3730Bad (EC)DHE parameters cause a client crashOpenSSL
CVE-2016-8610no title heldOpenSSL
CVE-2016-7054ChaCha20/Poly1305 heap-buffer-overflowOpenSSL
CVE-2016-7053CMS Null dereferenceOpenSSL
CVE-2011-4121no title heldOpenSSL extension of Ruby (Git trunk)

132 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.