PoC Index

CVE-2014-0160

KEVHIGH 7.5EPSS 100.0%

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
100.00% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2022-05-04
Nuclei
high
Published
2014-04-07
Updated
2025-10-22

Proof-of-concept exploits (61)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (4)

Vulhub environments (1)

Exploit collections (1)

References

Related