CVE detail
CVE-2014-0160
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
46 source links · newest first
Attackers continue to aggressively target small and mid-size businesses using high-profile vulnerabilities dating back a decade or more, network telemetry shows. Between January and March this year, five high-severity flaws stood out above all others in terms of their frequency in intrusion prevention system (IPS) data from SonicWall’s predominantly SMB customer base. At the top […]
newswww.csoonline.comApr 30, 2024, 6:00 AMHeartbleed made most certificates vulnerable. The future problem is that quantum decryption will make all certificates and everything else using RSA encryption vulnerable to everyone.
newswww.securityweek.comApr 2, 2024, 11:00 AM- November 2022 Patch Tuesday forecast: Wrapping up loose ends?Help Net Security
October 2022 Patch Tuesday was a little unusual last month, as it ‘kind of’ repeated itself the following week. Microsoft turned around and released a series of non-security updates that fixed some discovered connections issues – forcing many to conduct another unplanned patch cycle. They also left several zero-day vulnerabilities unresolved keeping us wondering when these open items will be resolved. November could be an important Patch Tuesday to wrap up these loose ends. OpenSSL … More →
newswww.helpnetsecurity.comNov 4, 2022, 6:25 AM Some are already drawing comparisons between the upcoming announcement and 2014’s Heartbleed vulnerability, tracked as CVE-2014-0160 , which garnered widespread media attention and concern in 2014 as it allowed threat actors to view data on any website utilising OpenSSL. RELATED RESOURCE The financial services survival guide How uncertainty and disru
newswww.itpro.comOct 28, 2022, 10:39 AM- OpenSSL to fix the second critical flaw everSecurity Affairs
The OpenSSL Project announced an upcoming update to address a critical vulnerability in the open-source toolkit. The OpenSSL Project announced that it is going to release updates to address a critical vulnerability in the open-source toolkit. Experts pointed out that it is the first critical vulnerability patched in toolkit since September 2016. “The OpenSSL project […]
newssecurityaffairs.comOct 26, 2022, 11:00 PM What is Heartbleed? Heartbleed is a vulnerability in OpenSSL that came to light in April of 2014; it was present on thousands of web servers, including those running major sites like Yahoo. OpenSSL is an open source code library that implements the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols. The vulnerability meant […]
newswww.csoonline.comSep 6, 2022, 8:00 AMThe last decade has seen its fair share of watershed moments that have had major implications on the cybersecurity landscape. Severe vulnerabilities, mass exploitations, and widespread cyberattacks have reshaped many aspects of modern security. To take stock of the past 10 years, cybersecurity vendor Trustwave has published the Decade Retrospective: The State of Vulnerabilities blog […]
newswww.csoonline.comJul 19, 2022, 9:00 AM- 246869 Windows systems are still vulnerable to the BlueKeep flawSecurity Affairs
In May 2019, Microsoft disclosed the BlueKeep vulnerability, more than a year later over 245,000 Windows systems still remain unpatched. Over a year ago Microsoft Patch Tuesday updates for May 2019 addressed nearly 80 vulnerabilities, including the BlueKeep flaw. The issue is a remote code execution flaw in Remote Desktop Services (RDS) that can be exploited by […]
newssecurityaffairs.comNov 17, 2020, 12:03 PM Most people will immediately recognize CVE-2014-0160 as a vulnerability, but few will know which vulnerability it refers to. Call it Heartbleed , however, and more people will know more about it. That’s the strength of natural language over numbers — humans remember words more easily than numbers.
newswww.securityweek.comNov 3, 2020, 6:49 PM- Evolution of OpenSSL Security After HeartbleedSecurityWeek
OpenSSL has evolved a great deal in terms of security since the disclosure of the Heartbleed vulnerability back in 2014.
newswww.securityweek.comDec 26, 2019, 1:28 PM - Coinhive stops digging, but cryptomining still dominatesHelp Net Security
While cryptomining services such as Coinhive have closed down, cryptominers are still the most prevalent malware aimed at organizations globally, according to the Check Point Global Threat Index for March 2019. As announced last month, both Coinhive and Authedmine stopped their mining services on March 8th. For the first time since December 2017, Coinhive dropped from the Index’s top position but, despite having only operated for eight days in March, it was still the 6th … More →
newswww.helpnetsecurity.comApr 10, 2019, 5:15 AM - Researchers unveil February 2019’s most wanted malwareHelp Net Security
Coinhive has once again led Check Point’s Global Threat Index for the 15th consecutive month, despite the announcement that its services have been shut down from March 8th 2019. GandCrab ransomware Researchers have also discovered several widespread campaigns distributing the GandCrab ransomware that have targeted Japan, Germany, Canada and Australia. These nations are just part of the targeted countries. These operations have emerged over the last two months, and Check Point’s researchers noticed a new … More →
newswww.helpnetsecurity.comMar 12, 2019, 6:15 AM - Most wanted malware in January 2019: A new threat speaks upHelp Net Security
Check Point’s Global Threat Index for January 2019 reveals a new backdoor Trojan affecting Linux servers, which is distributing the XMRig crypto-miner. The new malware, dubbed SpeakUp, is capable of delivering any payload and executing it on compromised machines. The new Trojan currently evades all security vendors’ anti-virus software. It has been propagated through a series of exploitations based on commands it receives from its control center, including the 8th most popular exploited vulnerability, “Command … More →
newswww.helpnetsecurity.comFeb 14, 2019, 6:15 AM - SmokeLoader malware downloader enters list of most wanted malwareHelp Net Security
Check Point has published its latest Global Threat Index for December 2018. The index reveals that SmokeLoader, a second-stage downloader known to researchers since 2011, rose 11 places in December to enter the Index’s top 10 at ninth place. After a surge of activity in the Ukraine and Japan, its global impact grew by 20. SmokeLoader is mainly used to load other malware, such as Trickbot Banker, AZORult Infostealer and Panda Banker. Cryptomining malware continues … More →
newswww.helpnetsecurity.comJan 15, 2019, 6:00 AM - FlawedAmmy: Dangerous RAT enteres most wanted malware listHelp Net Security
The latest Check Point Global Threat Index reveals that while cryptomining malware continues to dominate the rankings, a remote access Trojan has reached the top ten’s list for the first time. During the month of October, Check Point researchers discovered a widespread malware campaign spreading a remote access trojan (dubbed “FlawedAmmy”) that allows attackers to take over victims’ computers and data. The campaign was the latest and most widespread delivering the ‘FlawedAmmyy’ RAT, following a … More →
newswww.helpnetsecurity.comNov 14, 2018, 6:15 AM - Banking Trojan attacks increase, large scale Ramnit campaign impacts organizations worldwideHelp Net Security
Check Point revealed a significant increase in attacks using the Ramnit banking trojan. Ramnit has doubled its global impact over the past few months, driven by a large scale campaign that has been converting victim’s machines into malicious proxy servers. Ramnit “black” botnet geography During August 2018, Ramnit became the most prevalent banking Trojan in an upward trend in the use of banking Trojans that has more than doubled since June 2018. “This is the … More →
newswww.helpnetsecurity.comSep 12, 2018, 5:45 AM Crooks are attempting to exploit a recently patched Drupal vulnerability, tracked as CVE-2018-7602, to drop Monero mining malware onto vulnerable systems. The CVE-2018-7602 flaw is a highly critical remote code execution issue, also known as Drupalgeddon3, that was addressed by the Drupal team in April with the release of versions 7.59, 8.4.8 and 8.5.3. The security patch for the […]
newssecurityaffairs.comJun 22, 2018, 5:19 PM- Hackers Exploit Drupal Flaw for Monero MiningSecurityWeek
Network attacks exploiting a recently patched Drupal vulnerability are attempting to drop Monero mining malware onto vulnerable systems, Trend Micro reports.
newswww.securityweek.comJun 22, 2018, 12:21 PM More than two years after the disclosure of the HeartBleed bug, 200,000 services are still affected. Systems susceptible to Heartbleed attacks are still too many, despite the flaw was discovered in 2014 nearly 200,000 systems are still affected. Shodan made a similar search in November 2015 when he found 238,000 results, the number dropped to 237,539 […]
newssecurityaffairs.comJan 23, 2017, 8:50 PM- Heartbleed Still Affects 200,000 Devices: ShodanSecurityWeek
While the number of services affected by the OpenSSL flaw known as Heartbleed has decreased, the Shodan search engine has still found nearly 200,000 vulnerable devices.
newswww.securityweek.comJan 23, 2017, 3:00 PM There’s a new vulnerability set for disclosure in April called Badlock. Not much is known about the vulnerability itself, but deleted tweets have offered a key clue as to its impact. Complete with a logo and domain, Badlock looks to be yet another example of a hyped-up and marketed vulnerability. As it exists today, the […]
newswww.csoonline.comMar 23, 2016, 9:10 AMA high severity vulnerability revealed last week that affects HTTPS and other services that rely on SSL and TLS has not been patched by most affected cloud services, according to a recent scan.
newswww.securityweek.comMar 11, 2016, 4:31 PMAccording to research from Venafi, a vast majority of the world’s top businesses are still vulnerable to Heartbleed, which was disclosed a year ago this month. The OpenSSL flaw impacted organizations both large and small, but the latest figures show that 74-percent of the Global 2000 remain vulnerable. Heartbleed (CVE-2014-0160) was fully disclosed on April […]
newswww.csoonline.comApr 7, 2015, 8:32 PMHeartbleed Anniversary : Many Organizations’ External Servers Remain Vulnerable to Cyber Attacks As we mark the one-year anniversary of disclosure of the now famous OpenSSL vulnerability ( CVE-2014-0160) known as Heartbleed , security firm Venafi has released new research that shows how vulnerable Global 2000 organizations still are as a result of the flaw. According to Venafi’s research, as of April 2015, 74% of organizations have failed to completely remediate the risks around Heartlbeed despite ongoing warnings and guidance from software makers and security industry experts. That number remains nearly unchanged from the 76 percent reported by Venafi as being vulnerable as of August 2014. To compile its report, Venafi Labs used its cloud-based digital certificate reputation service to evaluate 1,642 Global 2000 organizations with public-facing systems vulnerable to Heartbleed. While many Global 2000 organizations have taken basic steps to remediate Heartbleed, most have not entirely…
newswww.securityweek.comApr 7, 2015, 6:48 PMIt appears that 2014 will be remembered in the IT industry for several severe and wide-reaching server-side vulnerabilities. In April, a serious flaw ( CVE-2014-0160 ) in the widely-used OpenSSL encryption software that protects website traffic shook the industry (a.k.a. Heartbleed), leaving hundreds of thousands of systems open to attacks from cybercriminals. More than six months later, thousands of websites and devices still remain vulnerable . In September, multiple critical vulnerabilities ( CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277 and CVE 2014-6278 ) were reported in the GNU Bourne-Again Shell (Bash), the common command-line shell used in many Linux / UNIX operating systems and Apple’s Mac OS X. The flaws could allow an attacker to remotely execute shell commands by attaching malicious code in environment variables used by the operating system. Similar to Heartbleed, these flaws affect a broad range of systems, including but not limited to Apache…
newswww.securityweek.comNov 5, 2014, 3:18 PMGoogle has released a new network traffic security testing tool that can be used to check if devices and applications are impacted by Transport Layer Security/ Secure Sockets Layer (TLS/SSL) vulnerabilities and if the cryptographic protocols are configured correctly.
newswww.securityweek.comNov 5, 2014, 2:21 PMA few months after details of the Heartbleed vulnerability surfaced, OpenSSL published a document outlining the project’s various objectives. One of those objectives was met on Sunday with the release of the organization’s first security policy.
newswww.securityweek.comSep 9, 2014, 7:00 PMYesterday, TrustedSec, a security consultancy based on Ohio, wrote that the recent breach at Community Health Systems (CHS) was the result of exploitation of the Heartbleed OpenSSL vulnerability (CVE-2014-0160). CHS’s 8-K filing on Monday did not reveal how the attackers got into their network, only that the records of approximately 4.5 million patients were stolen in
vendorunit42.paloaltonetworks.comAug 20, 2014, 8:50 PMAccording to a blog post from TrustedSec, an information security consultancy in Ohio, the breach at Community Health Systems (CHS) is the result of attackers targeting a flaw OpenSSL, CVE-2014-0160, better known as Heartbleed. The incident marks the first case Heartbleed has been linked to an attack of this size and type. On Monday, CHS […]
newswww.csoonline.comAug 20, 2014, 12:44 AMSSL encryption, especially services using OpenSSL, was brought into the spotlight more than ever this year.
newswww.securityweek.comJun 9, 2014, 1:19 PMIt’s been a month since the Heartbleed Bug set off a stampede to patch software in everything from network gear to security software as it quickly became evident that vulnerable versions of the OpenSSL encryption code had been very widely deployed. Two Reasons why Heartbleed doesn’t really change anything Heartbleed (CVE-2014-0160): An overview of […]
newswww.csoonline.comMay 9, 2014, 1:38 PM- Oracle Issues Heartbleed UpdatesSecurityWeek
Oracle issued an advisory today listing both security updates and detailing what is known and unknown about the Heartbleed vulnerability’s impact on Oracle products.
newswww.securityweek.comApr 21, 2014, 8:51 PM - Oracle patches 104 vulns, still working on some Heartbleed fixesHelp Net Security
Oracle’s April 2014 Critical Patch Update has been released, and solves a total of 104 vulnerabilities found across many of its products, including Oracle Database, Oracle Fusion Middleware, Oracle Hyperion, Oracle Supply Chain Product Suite, Oracle iLearning, Oracle PeopleSoft Enterprise, Oracle Siebel CRM, Oracle Java SE, Oracle and Sun Systems Products Suite, Oracle Linux and Virtualization, and Oracle MySQL. The most important ones for regular users are the patches addressing 37 vulnerabilities in Java SE, … More →
newswww.helpnetsecurity.comApr 17, 2014, 2:39 AM - Can Heartbleed be used in DDoS attacks?CSO Online
With nearly every major threat to information security, it is not long before security experts ask the question, “Can the threat play a role in distributed denial of service (DDoS) attacks?” When it comes to Heartbleed, some people are screaming that the sky is falling, but it is more complicated than that. Software vulnerabilities can cause […]
newswww.csoonline.comApr 16, 2014, 10:38 PM In a statement on Monday, the Canada Revenue Agency (CRA), Canada’s tax-collection agency, confirmed that the Heartbleed vulnerability was to blame for the loss of tax-related information. Last week, the CRA made headlines when they shutdown access to parts of its website, partly as a precaution, due to the concern created by the Heartbleed vulnerability. […]
newswww.csoonline.comApr 14, 2014, 4:52 PM- How many mobile Users could be affected by Heartbleed flaw?Security Affairs
Heartbleed is the security flaw that is scaring IT industry, which is its impact on the mobile worlds? How many Smartphone Users could be affected? Heartbleed flaw is the argument that most of all is capturing the attention of the media in this period, billions of users worldwide have been impacted, there are thousands solutions affected […]
newssecurityaffairs.comApr 14, 2014, 12:57 PM This has been a fun week. We have not had a significant cyber event like this – something that affects just about everybody on the Internet -- since the Kaminsky DNS vulnerability of 2008. Everybody I know has been scrambling to understand what it means to their organization, to their business and to their immediate
vendorunit42.paloaltonetworks.comApr 12, 2014, 1:25 PMThe Heartbleed Bug is probably the most serious menace to the modern Internet, a serious flaw in the popular OpenSSL library that is having a great impact. It’s been just over 48 hours after the disclosure of the news about the Heartbleed vulnerability, the serious flaw which affect OpenSSL library that allows an attacker to reveal […]
newssecurityaffairs.comApr 11, 2014, 7:02 AMTwitter was not affected by the Heartbleed Internet vulnerability that rocked the Web security world this week, making one less password consumers need to change to protect themselves, but users still need to be careful how they respond to the threat. Heartbleed is a bug in OpenSSL (Secure Sockets Layer), a tool for securing Web […]
newswww.csoonline.comApr 10, 2014, 1:23 PMA flaw buried deep inside a widely used cryptographic library has serious implications for Internet security. It’s very likely criminals may have had access to the sensitive data that was supposed to be protected in the first place.
newswww.securityweek.comApr 10, 2014, 1:07 PM- Users Affected the Most as Heartbleed Takes Center StageMalwarebytes Labs
[Update April 14, 2014 06:00 AM] We updated the list of services at the end of this post to include recently discovered…
newswww.malwarebytes.comApr 9, 2014, 5:00 PM - Heartbleed OpenSSL vulnerability: A technical remediationHelp Net Security
OpenSSL released an bug advisory about a 64kb memory leak patch in their library. The bug has been assigned CVE-2014-0160 TLS heartbeat read overrun. According to OpenSSL, the heartbeat extension was introduced in March 2012 with the release of version 1.0.1 of OpenSSL. This implies that the vulnerability has been around for just over 2 years. This is a very serious vulnerability that will allow protected information to be stolen even with the use of … More →
newswww.helpnetsecurity.comApr 9, 2014, 11:18 AM The Heartbleed Bug is a serious flaw in the popular OpenSSL library that allows an attacker to reveal up to 64kB of memory to a connected client or server. Experts which provide maintenance to OpenSSL library have patched a serious vulnerability (CVE-2014-0160) that allows an attacker to gain the access to 64 KB of memory […]
newssecurityaffairs.comApr 8, 2014, 6:36 PM- OpenSSL ‘Heartbleed’ Bug Leaks Sensitive DataSecurityWeek
Website owners should move quickly to patch a critical vulnerability (CVE-2014-0160) in the OpenSSL cryptographic software library.
newswww.securityweek.comApr 8, 2014, 5:09 PM - Heartbleed bug gets pluggedCSO Online
Cue the hyperbole and clapping monkeys. Today brings news to the screens of security folks the world over that OpenSSL has an OMG ZERO DAY AUUGGGGGHHHHH…oh, wait, there’s a fix. First off, what is the heartbleed bug? This bug, discovered by Neel Mehta from Google, is a weakness that is specific to the OpenSSL library. […]
newswww.csoonline.comApr 8, 2014, 1:05 PM Computer security experts are advising administrators to patch a severe flaw in a software library used by millions of websites to encrypt sensitive communications. The flaw, nicknamed “Heartbleed,” is contained in several versions of OpenSSL, a cryptographic library that enables SSL (Secure Sockets Layer) or TLS (Transport Security Layer) encryption. Most websites use either SSL […]
newswww.csoonline.comApr 8, 2014, 1:54 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2014-0224CVSS 7.4 · High
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers t…
- CVE-2021-44142CVSS 8.8 · High
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP filese…
- CVE-2014-9669CVSS 6.8 · Medium
Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have…
- CVE-2014-9658CVSS 7.5 · High
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (ou…
- CVE-2014-9657CVSS 7.5 · High
The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service…
- CVE-2020-25717CVSS 8.1 · High
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.