CVE-2014-0160
Description
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Out-of-bounds Read
DraftCommon Consequences
Applicable Platforms
OpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
VerifiedOpenSSL TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure
View Exploit Code →OpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory …
VerifiedOpenSSL 1.0.1f TLS Heartbeat Extension - 'Heartbleed' Memory Disclosure (Multiple SSL/TLS Versions)
View Exploit Code →OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak …
VerifiedOpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (1)
View Exploit Code →OpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak …
VerifiedOpenSSL TLS Heartbeat Extension - 'Heartbleed' Information Leak (2) (DTLS Support)
View Exploit Code →Micollab by Mitel
cpe:2.3:a:mitel:micollab:6.0:*:*:*:*:*:*:*
Debian Linux by Debian
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
Application Processing Engine Firmware by Siemens
cpe:2.3:o:siemens:application_processing_engine_firmware:2.0:*:*:*:*:*:*:*
Debian Linux by Debian
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
Symantec Messaging Gateway by Broadcom
cpe:2.3:a:broadcom:symantec_messaging_gateway:10.6.0:*:*:*:*:*:*:*
Enterprise Linux Server Aus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:*
Micollab by Mitel
cpe:2.3:a:mitel:micollab:7.0:*:*:*:*:*:*:*
Mivoice by Mitel
cpe:2.3:a:mitel:mivoice:1.3.2.2:*:*:*:*:skype_for_business:*:*
Mivoice by Mitel
cpe:2.3:a:mitel:mivoice:1.2.0.11:*:*:*:*:skype_for_business:*:*
Virtualization by Redhat
cpe:2.3:a:redhat:virtualization:6.0:*:*:*:*:*:*:*
Filezilla Server by Filezilla-Project
cpe:2.3:a:filezilla-project:filezilla_server:*:*:*:*:*:*:*:*
Enterprise Linux Server Eus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_eus:6.5:*:*:*:*:*:*:*
Mivoice by Mitel
cpe:2.3:a:mitel:mivoice:1.1.2.5:*:*:*:*:lync:*:*
Storage by Redhat
cpe:2.3:a:redhat:storage:2.1:*:*:*:*:*:*:*
Fedora by Fedoraproject
cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*
Gluster Storage by Redhat
cpe:2.3:a:redhat:gluster_storage:2.1:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
Simatic S7-1500T Firmware by Siemens
cpe:2.3:o:siemens:simatic_s7-1500t_firmware:1.5:*:*:*:*:*:*:*
V100 Firmware by Intellian
cpe:2.3:o:intellian:v100_firmware:1.24:*:*:*:*:*:*:*
Enterprise Linux Server Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_server_tus:6.5:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
V60 Firmware by Intellian
cpe:2.3:o:intellian:v60_firmware:1.15:*:*:*:*:*:*:*
Simatic S7-1500 Firmware by Siemens
cpe:2.3:o:siemens:simatic_s7-1500_firmware:1.5:*:*:*:*:*:*:*
Enterprise Linux Server by Redhat
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
Micollab by Mitel
cpe:2.3:a:mitel:micollab:7.2:*:*:*:*:*:*:*
S9922L Firmware by Ricon
cpe:2.3:o:ricon:s9922l_firmware:16.10.3\(3794\):*:*:*:*:*:*:*
Openssl by Openssl
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
Opensuse by Opensuse
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
V100 Firmware by Intellian
cpe:2.3:o:intellian:v100_firmware:1.20:*:*:*:*:*:*:*
Mivoice by Mitel
cpe:2.3:a:mitel:mivoice:1.1.3.3:*:*:*:*:skype_for_business:*:*
Wincc Open Architecture by Siemens
cpe:2.3:a:siemens:wincc_open_architecture:3.12:*:*:*:*:*:*:*
V100 Firmware by Intellian
cpe:2.3:o:intellian:v100_firmware:1.21:*:*:*:*:*:*:*
Cp 1543-1 Firmware by Siemens
cpe:2.3:o:siemens:cp_1543-1_firmware:1.1:*:*:*:*:*:*:*
Elan-8.2 by Siemens
cpe:2.3:a:siemens:elan-8.2:*:*:*:*:*:*:*:*
Micollab by Mitel
cpe:2.3:a:mitel:micollab:7.3:*:*:*:*:*:*:*
Debian Linux by Debian
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
V60 Firmware by Intellian
cpe:2.3:o:intellian:v60_firmware:1.25:*:*:*:*:*:*:*
Symantec Messaging Gateway by Broadcom
cpe:2.3:a:broadcom:symantec_messaging_gateway:10.6.1:*:*:*:*:*:*:*
Micollab by Mitel
cpe:2.3:a:mitel:micollab:7.1:*:*:*:*:*:*:*
Opensuse by Opensuse
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
Enterprise Linux Workstation by Redhat
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*
Mivoice by Mitel
cpe:2.3:a:mitel:mivoice:1.4.0.102:*:*:*:*:skype_for_business:*:*
Enterprise Linux Desktop by Redhat
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
Micollab by Mitel
cpe:2.3:a:mitel:micollab:7.3.0.104:*:*:*:*:*:*:*
Splunk by Splunk
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Fedora by Fedoraproject
cpe:2.3:o:fedoraproject:fedora:20:*:*:*:*:*:*:*