Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2014-0160 Details

Description

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0160 CISA-ADPUS Government Resource
http://advisories.mageia.org/MGASA-2014-0165.html CVEThird Party Advisory
http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/ CVEIssue TrackingThird Party Advisory
http://cogentdatahub.com/ReleaseNotes.html CVERelease Notes
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01 CVEBroken Link

see all 257 references

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

Vulnerability NameDate AddedDue DateRequired Action
OpenSSL Information Disclosure VulnerabilityMay 4, 2022May 25, 2022Apply updates per vendor instructions.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-125Out-of-bounds Read[email protected]
CWE-125Out-of-bounds ReadCISA-ADP

Affected Products

ProductVersions

Change History

38 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2014-0160
NVD Published Date:
Apr 7, 2014
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]