{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"state":"PUBLISHED","cveId":"CVE-2014-0160","assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","dateUpdated":"2025-10-22T00:05:38.217Z","dateReserved":"2013-12-03T00:00:00.000Z","datePublished":"2014-04-07T00:00:00.000Z"},"containers":{"cna":{"providerMetadata":{"orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat","dateUpdated":"2022-11-15T00:00:00.000Z"},"descriptions":[{"lang":"en","value":"The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug."}],"affected":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}],"references":[{"url":"https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html?sr=36517217"},{"name":"1030077","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id/1030077"},{"name":"20140408 heartbleed OpenSSL bug CVE-2014-0160","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2014/Apr/90"},{"url":"http://www.getchef.com/blog/2014/04/09/chef-server-heartbleed-cve-2014-0160-releases/"},{"name":"DSA-2896","tags":["vendor-advisory"],"url":"http://www.debian.org/security/2014/dsa-2896"},{"name":"HPSBGN03008","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139774054614965&w=2"},{"name":"HPSBMU03024","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139889113431619&w=2"},{"name":"RHSA-2014:0396","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0396.html"},{"name":"HPSBHF03021","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139835815211508&w=2"},{"name":"HPSBHF03136","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=141287864628122&w=2"},{"name":"VU#720951","tags":["third-party-advisory"],"url":"http://www.kb.cert.org/vuls/id/720951"},{"url":"http://www.splunk.com/view/SP-CAAAMB3"},{"name":"HPSBMU03033","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139905295427946&w=2"},{"url":"http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0"},{"url":"http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf"},{"name":"HPSBGN03011","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139833395230364&w=2"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21670161"},{"url":"http://www.vmware.com/security/advisories/VMSA-2014-0012.html"},{"name":"openSUSE-SU-2014:0492","tags":["vendor-advisory"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.html"},{"name":"SSRT101846","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=142660345230545&w=2"},{"name":"20140409 Re: heartbleed OpenSSL bug CVE-2014-0160","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2014/Apr/109"},{"name":"HPSBMU03037","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=140724451518351&w=2"},{"name":"1030080","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id/1030080"},{"name":"57836","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/57836"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=isg400001843"},{"name":"HPSBMU03012","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139808058921905&w=2"},{"name":"HPSBST03001","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139758572430452&w=2"},{"name":"66690","tags":["vdb-entry"],"url":"http://www.securityfocus.com/bid/66690"},{"url":"http://www.innominate.com/data/downloads/manuals/mdm_1.5.2.1_Release_Notes.pdf"},{"url":"https://filezilla-project.org/versions.php?type=server"},{"name":"HPSBMU03023","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139843768401936&w=2"},{"name":"57483","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/57483"},{"name":"20140409 OpenSSL Heartbeat Extension Vulnerability in Multiple Cisco Products","tags":["vendor-advisory"],"url":"http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-heartbleed"},{"url":"http://www.kerio.com/support/kerio-control/release-history"},{"url":"http://advisories.mageia.org/MGASA-2014-0165.html"},{"url":"http://www.blackberry.com/btsc/KB35882"},{"name":"HPSBHF03293","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=142660345230545&w=2"},{"name":"HPSBMU03044","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=140075368411126&w=2"},{"name":"HPSBMU03030","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139905351928096&w=2"},{"name":"1030081","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id/1030081"},{"name":"FEDORA-2014-4879","tags":["vendor-advisory"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.html"},{"name":"20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","tags":["mailing-list"],"url":"http://www.securityfocus.com/archive/1/534161/100/0/threaded"},{"name":"FEDORA-2014-4910","tags":["vendor-advisory"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.html"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1084875"},{"name":"FEDORA-2014-9308","tags":["vendor-advisory"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=isg400001841"},{"name":"HPSBMU03013","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139824993005633&w=2"},{"name":"1030079","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id/1030079"},{"name":"RHSA-2014:0377","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0377.html"},{"name":"HPSBMU02995","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139722163017074&w=2"},{"name":"HPSBPI03031","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139889295732144&w=2"},{"url":"https://code.google.com/p/mod-spdy/issues/detail?id=85"},{"name":"HPSBMU02999","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139765756720506&w=2"},{"name":"HPSBGN03010","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139774703817488&w=2"},{"name":"HPSBMU03029","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139905202427693&w=2"},{"url":"http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/"},{"url":"http://heartbleed.com/"},{"name":"HPSBMU03018","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139817782017443&w=2"},{"url":"http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01"},{"name":"HPSBMU03040","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=140015787404650&w=2"},{"url":"http://cogentdatahub.com/ReleaseNotes.html"},{"name":"HPSBMU03025","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139869720529462&w=2"},{"name":"HPSBST03016","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139842151128341&w=2"},{"name":"HPSBMU03028","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139905243827825&w=2"},{"name":"HPSBMU03009","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139905458328378&w=2"},{"url":"http://www.f-secure.com/en/web/labs_global/fsc-2014-1"},{"name":"TA14-098A","tags":["third-party-advisory"],"url":"http://www.us-cert.gov/ncas/alerts/TA14-098A"},{"name":"57347","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/57347"},{"name":"[syslog-ng-announce] 20140411 syslog-ng Premium Edition 5 LTS (5.0.4a) has been released","tags":["mailing-list"],"url":"https://lists.balabit.hu/pipermail/syslog-ng-announce/2014-April/000184.html"},{"name":"20140411 MRI Rubies may contain statically linked, vulnerable OpenSSL","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2014/Apr/173"},{"url":"https://blog.torproject.org/blog/openssl-bug-cve-2014-0160"},{"url":"http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html"},{"url":"http://www.oracle.com/technetwork/topics/security/opensslheartbleedcve-2014-0160-2188454.html"},{"url":"https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html"},{"url":"http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3"},{"name":"HPSBST03000","tags":["vendor-advisory"],"url":"https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04260637-4%257CdocLocale%253Den_US%257CcalledBy%253DSearch_Result&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken"},{"name":"20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2014/Dec/23"},{"name":"HPSBST03004","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139905653828999&w=2"},{"name":"USN-2165-1","tags":["vendor-advisory"],"url":"http://www.ubuntu.com/usn/USN-2165-1"},{"name":"RHSA-2014:0378","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0378.html"},{"name":"HPSBMU02997","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139757919027752&w=2"},{"name":"SUSE-SA:2014:002","tags":["vendor-advisory"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00005.html"},{"name":"32764","tags":["exploit"],"url":"http://www.exploit-db.com/exploits/32764"},{"name":"HPSBMU02994","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139757726426985&w=2"},{"url":"http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160512_00"},{"name":"HPSBMU03022","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139869891830365&w=2"},{"name":"HPSBST03027","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139905868529690&w=2"},{"name":"HPSBMU03019","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139817685517037&w=2"},{"name":"HPSBMU03062","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=140752315422991&w=2"},{"name":"20140408 Re: heartbleed OpenSSL bug CVE-2014-0160","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2014/Apr/91"},{"name":"1030078","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id/1030078"},{"name":"59243","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/59243"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004661"},{"name":"HPSBMU03020","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139836085512508&w=2"},{"name":"HPSBST03015","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139824923705461&w=2"},{"name":"RHSA-2014:0376","tags":["vendor-advisory"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0376.html"},{"name":"HPSBPI03014","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139835844111589&w=2"},{"name":"MDVSA-2015:062","tags":["vendor-advisory"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2015:062"},{"url":"https://www.cert.fi/en/reports/2014/vulnerability788210.html"},{"name":"57721","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/57721"},{"name":"57968","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/57968"},{"url":"http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/"},{"url":"http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=3"},{"name":"openSUSE-SU-2014:0560","tags":["vendor-advisory"],"url":"http://lists.opensuse.org/opensuse-updates/2014-04/msg00061.html"},{"name":"HPSBMU03032","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139905405728262&w=2"},{"name":"1030082","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id/1030082"},{"name":"HPSBMU02998","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139757819327350&w=2"},{"name":"32745","tags":["exploit"],"url":"http://www.exploit-db.com/exploits/32745"},{"name":"20140412 Re: heartbleed OpenSSL bug CVE-2014-0160","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2014/Apr/190"},{"url":"http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/"},{"name":"HPSBMU03017","tags":["vendor-advisory"],"url":"http://marc.info/?l=bugtraq&m=139817727317190&w=2"},{"url":"https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-17-0008"},{"url":"http://www.openssl.org/news/secadv_20140407.txt"},{"url":"https://gist.github.com/chapmajs/10473815"},{"url":"http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=1"},{"name":"1030074","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id/1030074"},{"url":"http://support.citrix.com/article/CTX140605"},{"name":"59139","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/59139"},{"url":"http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/"},{"name":"57966","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/57966"},{"name":"1030026","tags":["vdb-entry"],"url":"http://www.securitytracker.com/id/1030026"},{"name":"59347","tags":["third-party-advisory"],"url":"http://secunia.com/advisories/59347"},{"name":"[tomcat-dev] 20190319 svn commit: r1855831 [26/30] - in /tomcat/site/trunk: ./ docs/ xdocs/","tags":["mailing-list"],"url":"https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E"},{"name":"[tomcat-dev] 20190325 svn commit: r1856174 [26/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/","tags":["mailing-list"],"url":"https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E"},{"url":"https://sku11army.blogspot.com/2020/01/heartbleed-hearts-continue-to-bleed.html"},{"name":"[tomcat-dev] 20200203 svn commit: r1873527 [26/30] - /tomcat/site/trunk/docs/","tags":["mailing-list"],"url":"https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-635659.pdf"},{"name":"[tomcat-dev] 20200213 svn commit: r1873980 [31/34] - /tomcat/site/trunk/docs/","tags":["mailing-list"],"url":"https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E"},{"url":"https://yunus-shn.medium.com/ricon-industrial-cellular-router-heartbleed-attack-2634221c02bd"}],"problemTypes":[{"descriptions":[{"type":"text","lang":"en","description":"n/a"}]}],"datePublic":"2014-04-07T00:00:00.000Z"},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-06T09:05:39.056Z"},"title":"CVE Program Container","references":[{"url":"https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html?sr=36517217","tags":["x_transferred"]},{"name":"1030077","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id/1030077"},{"name":"20140408 heartbleed OpenSSL bug CVE-2014-0160","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2014/Apr/90"},{"url":"http://www.getchef.com/blog/2014/04/09/chef-server-heartbleed-cve-2014-0160-releases/","tags":["x_transferred"]},{"name":"DSA-2896","tags":["vendor-advisory","x_transferred"],"url":"http://www.debian.org/security/2014/dsa-2896"},{"name":"HPSBGN03008","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139774054614965&w=2"},{"name":"HPSBMU03024","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139889113431619&w=2"},{"name":"RHSA-2014:0396","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0396.html"},{"name":"HPSBHF03021","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139835815211508&w=2"},{"name":"HPSBHF03136","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=141287864628122&w=2"},{"name":"VU#720951","tags":["third-party-advisory","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/720951"},{"url":"http://www.splunk.com/view/SP-CAAAMB3","tags":["x_transferred"]},{"name":"HPSBMU03033","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139905295427946&w=2"},{"url":"http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0","tags":["x_transferred"]},{"url":"http://www.apcmedia.com/salestools/SJHN-7RKGNM/SJHN-7RKGNM_R4_EN.pdf","tags":["x_transferred"]},{"name":"HPSBGN03011","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139833395230364&w=2"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21670161","tags":["x_transferred"]},{"url":"http://www.vmware.com/security/advisories/VMSA-2014-0012.html","tags":["x_transferred"]},{"name":"openSUSE-SU-2014:0492","tags":["vendor-advisory","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00004.html"},{"name":"SSRT101846","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=142660345230545&w=2"},{"name":"20140409 Re: heartbleed OpenSSL bug CVE-2014-0160","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2014/Apr/109"},{"name":"HPSBMU03037","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=140724451518351&w=2"},{"name":"1030080","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id/1030080"},{"name":"57836","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/57836"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=isg400001843","tags":["x_transferred"]},{"name":"HPSBMU03012","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139808058921905&w=2"},{"name":"HPSBST03001","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139758572430452&w=2"},{"name":"66690","tags":["vdb-entry","x_transferred"],"url":"http://www.securityfocus.com/bid/66690"},{"url":"http://www.innominate.com/data/downloads/manuals/mdm_1.5.2.1_Release_Notes.pdf","tags":["x_transferred"]},{"url":"https://filezilla-project.org/versions.php?type=server","tags":["x_transferred"]},{"name":"HPSBMU03023","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139843768401936&w=2"},{"name":"57483","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/57483"},{"name":"20140409 OpenSSL Heartbeat Extension Vulnerability in Multiple Cisco Products","tags":["vendor-advisory","x_transferred"],"url":"http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20140409-heartbleed"},{"url":"http://www.kerio.com/support/kerio-control/release-history","tags":["x_transferred"]},{"url":"http://advisories.mageia.org/MGASA-2014-0165.html","tags":["x_transferred"]},{"url":"http://www.blackberry.com/btsc/KB35882","tags":["x_transferred"]},{"name":"HPSBHF03293","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=142660345230545&w=2"},{"name":"HPSBMU03044","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=140075368411126&w=2"},{"name":"HPSBMU03030","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139905351928096&w=2"},{"name":"1030081","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id/1030081"},{"name":"FEDORA-2014-4879","tags":["vendor-advisory","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131221.html"},{"name":"20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","tags":["mailing-list","x_transferred"],"url":"http://www.securityfocus.com/archive/1/534161/100/0/threaded"},{"name":"FEDORA-2014-4910","tags":["vendor-advisory","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-April/131291.html"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1084875","tags":["x_transferred"]},{"name":"FEDORA-2014-9308","tags":["vendor-advisory","x_transferred"],"url":"http://lists.fedoraproject.org/pipermail/package-announce/2014-August/136473.html"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=isg400001841","tags":["x_transferred"]},{"name":"HPSBMU03013","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139824993005633&w=2"},{"name":"1030079","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id/1030079"},{"name":"RHSA-2014:0377","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0377.html"},{"name":"HPSBMU02995","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139722163017074&w=2"},{"name":"HPSBPI03031","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139889295732144&w=2"},{"url":"https://code.google.com/p/mod-spdy/issues/detail?id=85","tags":["x_transferred"]},{"name":"HPSBMU02999","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139765756720506&w=2"},{"name":"HPSBGN03010","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139774703817488&w=2"},{"name":"HPSBMU03029","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139905202427693&w=2"},{"url":"http://www.getchef.com/blog/2014/04/09/chef-server-11-0-12-release/","tags":["x_transferred"]},{"url":"http://heartbleed.com/","tags":["x_transferred"]},{"name":"HPSBMU03018","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139817782017443&w=2"},{"url":"http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01","tags":["x_transferred"]},{"name":"HPSBMU03040","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=140015787404650&w=2"},{"url":"http://cogentdatahub.com/ReleaseNotes.html","tags":["x_transferred"]},{"name":"HPSBMU03025","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139869720529462&w=2"},{"name":"HPSBST03016","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139842151128341&w=2"},{"name":"HPSBMU03028","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139905243827825&w=2"},{"name":"HPSBMU03009","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139905458328378&w=2"},{"url":"http://www.f-secure.com/en/web/labs_global/fsc-2014-1","tags":["x_transferred"]},{"name":"TA14-098A","tags":["third-party-advisory","x_transferred"],"url":"http://www.us-cert.gov/ncas/alerts/TA14-098A"},{"name":"57347","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/57347"},{"name":"[syslog-ng-announce] 20140411 syslog-ng Premium Edition 5 LTS (5.0.4a) has been released","tags":["mailing-list","x_transferred"],"url":"https://lists.balabit.hu/pipermail/syslog-ng-announce/2014-April/000184.html"},{"name":"20140411 MRI Rubies may contain statically linked, vulnerable OpenSSL","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2014/Apr/173"},{"url":"https://blog.torproject.org/blog/openssl-bug-cve-2014-0160","tags":["x_transferred"]},{"url":"http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html","tags":["x_transferred"]},{"url":"http://www.oracle.com/technetwork/topics/security/opensslheartbleedcve-2014-0160-2188454.html","tags":["x_transferred"]},{"url":"https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html","tags":["x_transferred"]},{"url":"http://git.openssl.org/gitweb/?p=openssl.git%3Ba=commit%3Bh=96db9023b881d7cd9f379b0c154650d6c108e9a3","tags":["x_transferred"]},{"name":"HPSBST03000","tags":["vendor-advisory","x_transferred"],"url":"https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04260637-4%257CdocLocale%253Den_US%257CcalledBy%253DSearch_Result&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken"},{"name":"20141205 NEW: VMSA-2014-0012 - VMware vSphere product updates address security vulnerabilities","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2014/Dec/23"},{"name":"HPSBST03004","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139905653828999&w=2"},{"name":"USN-2165-1","tags":["vendor-advisory","x_transferred"],"url":"http://www.ubuntu.com/usn/USN-2165-1"},{"name":"RHSA-2014:0378","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0378.html"},{"name":"HPSBMU02997","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139757919027752&w=2"},{"name":"SUSE-SA:2014:002","tags":["vendor-advisory","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2014-04/msg00005.html"},{"name":"32764","tags":["exploit","x_transferred"],"url":"http://www.exploit-db.com/exploits/32764"},{"name":"HPSBMU02994","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139757726426985&w=2"},{"url":"http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160512_00","tags":["x_transferred"]},{"name":"HPSBMU03022","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139869891830365&w=2"},{"name":"HPSBST03027","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139905868529690&w=2"},{"name":"HPSBMU03019","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139817685517037&w=2"},{"name":"HPSBMU03062","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=140752315422991&w=2"},{"name":"20140408 Re: heartbleed OpenSSL bug CVE-2014-0160","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2014/Apr/91"},{"name":"1030078","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id/1030078"},{"name":"59243","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/59243"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=ssg1S1004661","tags":["x_transferred"]},{"name":"HPSBMU03020","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139836085512508&w=2"},{"name":"HPSBST03015","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139824923705461&w=2"},{"name":"RHSA-2014:0376","tags":["vendor-advisory","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2014-0376.html"},{"name":"HPSBPI03014","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139835844111589&w=2"},{"name":"MDVSA-2015:062","tags":["vendor-advisory","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDVSA-2015:062"},{"url":"https://www.cert.fi/en/reports/2014/vulnerability788210.html","tags":["x_transferred"]},{"name":"57721","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/57721"},{"name":"57968","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/57968"},{"url":"http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/","tags":["x_transferred"]},{"url":"http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=3","tags":["x_transferred"]},{"name":"openSUSE-SU-2014:0560","tags":["vendor-advisory","x_transferred"],"url":"http://lists.opensuse.org/opensuse-updates/2014-04/msg00061.html"},{"name":"HPSBMU03032","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139905405728262&w=2"},{"name":"1030082","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id/1030082"},{"name":"HPSBMU02998","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139757819327350&w=2"},{"name":"32745","tags":["exploit","x_transferred"],"url":"http://www.exploit-db.com/exploits/32745"},{"name":"20140412 Re: heartbleed OpenSSL bug CVE-2014-0160","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2014/Apr/190"},{"url":"http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/","tags":["x_transferred"]},{"name":"HPSBMU03017","tags":["vendor-advisory","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=139817727317190&w=2"},{"url":"https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-17-0008","tags":["x_transferred"]},{"url":"http://www.openssl.org/news/secadv_20140407.txt","tags":["x_transferred"]},{"url":"https://gist.github.com/chapmajs/10473815","tags":["x_transferred"]},{"url":"http://public.support.unisys.com/common/public/vulnerability/NVD_Detail_Rpt.aspx?ID=1","tags":["x_transferred"]},{"name":"1030074","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id/1030074"},{"url":"http://support.citrix.com/article/CTX140605","tags":["x_transferred"]},{"name":"59139","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/59139"},{"url":"http://www.getchef.com/blog/2014/04/09/enterprise-chef-1-4-9-release/","tags":["x_transferred"]},{"name":"57966","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/57966"},{"name":"1030026","tags":["vdb-entry","x_transferred"],"url":"http://www.securitytracker.com/id/1030026"},{"name":"59347","tags":["third-party-advisory","x_transferred"],"url":"http://secunia.com/advisories/59347"},{"name":"[tomcat-dev] 20190319 svn commit: r1855831 [26/30] - in /tomcat/site/trunk: ./ docs/ xdocs/","tags":["mailing-list","x_transferred"],"url":"https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E"},{"name":"[tomcat-dev] 20190325 svn commit: r1856174 [26/29] - in /tomcat/site/trunk: docs/ xdocs/ xdocs/stylesheets/","tags":["mailing-list","x_transferred"],"url":"https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E"},{"url":"https://sku11army.blogspot.com/2020/01/heartbleed-hearts-continue-to-bleed.html","tags":["x_transferred"]},{"name":"[tomcat-dev] 20200203 svn commit: r1873527 [26/30] - /tomcat/site/trunk/docs/","tags":["mailing-list","x_transferred"],"url":"https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E"},{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-635659.pdf","tags":["x_transferred"]},{"name":"[tomcat-dev] 20200213 svn commit: r1873980 [31/34] - /tomcat/site/trunk/docs/","tags":["mailing-list","x_transferred"],"url":"https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E"},{"url":"https://yunus-shn.medium.com/ricon-industrial-cellular-router-heartbleed-attack-2634221c02bd","tags":["x_transferred"]}]},{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":7.5,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"NONE","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"id":"CVE-2014-0160","role":"CISA Coordinator","options":[{"Exploitation":"active"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2025-02-07T13:32:34.600181Z"}}},{"other":{"type":"kev","content":{"dateAdded":"2022-05-04","reference":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0160"}}}],"references":[{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0160","tags":["government-resource"]}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-125","description":"CWE-125 Out-of-bounds Read"}]}],"timeline":[{"time":"2022-05-04T00:00:00.000Z","lang":"en","value":"CVE-2014-0160 added to CISA KEV"}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-22T00:05:38.217Z"}}]}}