August 11, 2026

CVE Watchtower


← Back to CVE List

CVE-2014-0160NVD

Vulnerability Summary

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Severity Level
HIGH(7.5)
Published Date
Apr 7, 2014
Last Modified
Apr 21, 2026
Exploitation Status
ACTIVE
EPSS Score (30-Day)
94.46%Probability
Root Weakness (CWE)
The software reads data past the end, or before the beginning, of the intended buffer.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone

External References