CVE-2014-0160

high

Description

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

References

https://www.mitel.com/en-ca/support/security-advisories/mitel-product-security-advisory-17-0008

https://www.cert.fi/en/reports/2014/vulnerability788210.html

https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html?sr=36517217

https://support.f5.com/kb/en-us/solutions/public/15000/100/sol15159.html

https://lists.balabit.hu/pipermail/syslog-ng-announce/2014-April/000184.html

https://lists.apache.org/thread.html/rf8e8c091182b45daa50d3557cad9b10bb4198e3f08cf8f1c66a1b08d%40%3Cdev.tomcat.apache.org%3E

https://lists.apache.org/thread.html/re3b72cbb13e1dfe85c4a06959a3b6ca6d939b407ecca80db12b54220%40%3Cdev.tomcat.apache.org%3E

https://lists.apache.org/thread.html/f8e0814e11c7f21f42224b6de111cb3f5e5ab5c15b78924c516d4ec2%40%3Cdev.tomcat.apache.org%3E

https://lists.apache.org/thread.html/ba661b0edd913b39ff129a32d855620dd861883ade05fd88a8ce517d%40%3Cdev.tomcat.apache.org%3E

https://h20566.www2.hp.com/portal/site/hpsc/template.PAGE/public/kb/docDisplay/?spf_p.tpst=kbDocDisplay&spf_p.prp_kbDocDisplay=wsrp-navigationalState%3DdocId%253Demr_na-c04260637-4%257CdocLocale%253Den_US%257CcalledBy%253DSearch_Result&javax.portlet.begCacheTok=com.vignette.cachetoken&javax.portlet.endCacheTok=com.vignette.cachetoken

https://cert-portal.siemens.com/productcert/pdf/ssa-635659.pdf

https://bugzilla.redhat.com/show_bug.cgi?id=1084875

http://www.us-cert.gov/ncas/alerts/TA14-098A

http://www.ubuntu.com/usn/USN-2165-1

http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=&suid=20160512_00

http://www.splunk.com/view/SP-CAAAMB3

http://www.oracle.com/technetwork/topics/security/opensslheartbleedcve-2014-0160-2188454.html

http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html

http://www.mandriva.com/security/advisories?name=MDVSA-2015:062

http://www.kb.cert.org/vuls/id/720951

https://github.com/RenatoAntunovic/cve-metasploit-skeniranje

https://github.com/IhsSpotlight/HeartBleed-CVE-2014-0160--SCRIPTS-python3

https://github.com/A-dev9077/Week-05-Computer-Networking-Fundamentals-Network-Configuration

https://github.com/nickharris808/soundnessbench

https://github.com/AdnaKoss/cve-rag-assistant

https://github.com/T-Onix/Snare

https://github.com/tungduongNT/CVE-2014-0160.

https://github.com/Baiye-2004/cve-poc-collection

https://github.com/prafull97-lab/Cybersecurity-Vulnerability-Risk-Analysis

https://github.com/korneevscp/osint-target

https://github.com/shaswata09/cve2bf

https://github.com/Hector-Abarca/realrisk-checks

https://github.com/manahylkhan/cveradar

https://github.com/cemheren/quicksheet-cve-ext

https://github.com/Erik-Castro/DevSecurity

https://github.com/gadievron/cve-env

https://github.com/ashishghmr8848/CVE-Explained-For-Defenders

https://github.com/k4w-wak/ollama-silent-patches

https://github.com/Kartik0219/vuln-scanner

https://github.com/SallyAboud/Vulnerability-Scanner

https://github.com/staatik/fragchain-core

https://github.com/krish-achanta/vuln-validator

https://github.com/AtharvS7/RiskSense

https://github.com/Sreejith-nair511/FortressOne-satus

https://github.com/guilhermeferreira24/healthcare-cybersecurity-analysis

https://github.com/mrjoker-web/ShadowCVE

https://github.com/AswinMathew2004/cve-cli

https://github.com/AbdulMoiz6692/cve-vulnerability-scanner-pro

https://github.com/plusive27-max/cve-lookup

https://github.com/RehmanAjaz/CVE-Scanner

https://github.com/SamuelRedfern/CVE-Converter

https://github.com/Souf-F/cyber-notes

https://github.com/fankh/openorb-scanner

https://github.com/zaryouhashraf/CVE-2014-0160

https://github.com/0xAshwesker/CVE-2014-0160

https://github.com/Deloney-code/AI-Powered-Red-Team-Automation

https://github.com/ndouglas-cloudsmith/ExploitPwned

https://github.com/CVE-ORG/CVE-ORG

https://github.com/22imer/CVE-2014-0160

https://github.com/SimoesCTT/CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160

https://github.com/Arthurfert/SecLLM-Gen

https://github.com/sastraadiwiguna-purpleeliteteaming/CVE-2025-13834-A-Bluetooth-RFCOMM-Out-of-Bounds-Read-Vulnerability-in-Modern-Wireless-Devices

https://github.com/swesmith-repos/cve-search__PyCVESearch.6a492a72

https://github.com/brkothari/cve-analyzer

https://github.com/0wn2886/CVE-Web

https://github.com/Techryptic/ThreatPulse

https://github.com/JMG15111998/Common-Vulnerabilities-and-Exposures-CVEs-

https://github.com/uttambodara/Awesome-Hacking-Learning-Path

https://github.com/ozGod-sh/Declencheur-CVE

https://github.com/B1ack4sh/Blackash-CVE-2025-5777

https://github.com/ZTheH/netmap

https://github.com/ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration

https://github.com/Songul-Kizilay/CVE-2014-0346-

https://github.com/Songul-Kizilay/CVE-2014-0346

https://github.com/impoliteinte/go-msfdb

https://github.com/jlucas8/cve-test-scripts

https://github.com/PuddinCat/GithubRepoSpider

https://github.com/thoughtfulroc/go-msfdb

https://github.com/fkie-cad/nvd_json_bot

https://github.com/Yash-Thakkar77/CVE-2014-0160-HeartBleed

https://github.com/mrhili/CVE-SEARCH-NVD

https://github.com/orhun/flawz

https://github.com/Orange-OpenSource/decret

https://github.com/cbk914/heartbleed-checker

https://github.com/GardeniaWhite/fuzzing

https://github.com/yonhan3/openssl-cve

https://github.com/stackviolator/goHeartBleed

https://github.com/pierceoneill/bleeding-heart

https://github.com/BelminD/heartbleed

https://github.com/ingochris/heartpatch.us

https://github.com/nyc-tophile/A2SV--SSL-VUL-Scan

https://github.com/clic-kbait/A2SV--SSL-VUL-Scan

https://github.com/rouze-d/heartbleed

https://github.com/ForAllSecure/VulnerabilitiesLab

https://github.com/vulsio/go-msfdb

https://github.com/s-index/go-cve-search

https://github.com/ThanHuuTuan/Heartexploit

https://github.com/cldme/heartbleed-bug

https://github.com/cheese-hub/heartbleed

https://github.com/Saymeis/HeartBleed

https://github.com/cve-search/PyCVESearch

https://github.com/vulsio/go-cve-dictionary

https://github.com/hybridus/heartbleedscanner

https://github.com/barnumbirr/ares

https://github.com/iSCInc/heartbleed

https://github.com/xanas/heartbleed.py

https://github.com/vortextube/ssl_scanner

https://github.com/OffensivePython/HeartLeak

https://github.com/DisK0nn3cT/MaltegoHeartbleed

https://github.com/yryz/heartbleed.js

https://github.com/mozilla-services/Heartbleed

https://github.com/einaros/heartbleed-tools

https://github.com/indiw0rm/-Heartbleed-

https://github.com/xlucas/heartbleed

https://github.com/GeeksXtreme/ssl-heartbleed.nse

https://github.com/idkqh7/heatbleeding

https://github.com/wwwiretap/bleeding_onions

https://github.com/a0726h77/heartbleed-test

https://github.com/sammyfung/openssl-heartbleed-fix

https://github.com/siddolo/knockbleed

https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker

https://github.com/amerine/coronary

https://github.com/proactiveRISK/heartbleed-extention

https://github.com/sensepost/heartbleed-poc

https://github.com/zouguangxian/heartbleed

https://github.com/roganartu/heartbleedchecker-chrome

https://github.com/takeshixx/ssl-heartbleed.nse

https://github.com/fb1h2s/CVE-2014-0160

https://github.com/isgroup/openmagic

https://github.com/iwaffles/heartbleed-test.crx

https://github.com/Lekensteyn/pacemaker

https://github.com/musalbas/heartbleed-masstest

https://github.com/cyphar/heartthreader

https://github.com/DominikTo/bleed

https://github.com/titanous/heartbleeder

https://github.com/FiloSottile/Heartbleed

https://yunus-shn.medium.com/ricon-industrial-cellular-router-heartbleed-attack-2634221c02bd

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0160

https://sku11army.blogspot.com/2020/01/heartbleed-hearts-continue-to-bleed.html

https://gist.github.com/chapmajs/10473815

https://filezilla-project.org/versions.php?type=server

https://code.google.com/p/mod-spdy/issues/detail?id=85

https://blog.torproject.org/blog/openssl-bug-cve-2014-0160

http://www.websense.com/support/article/kbarticle/Vulnerabilities-resolved-in-TRITON-APX-Version-8-0

http://www.vmware.com/security/advisories/VMSA-2014-0012.html

http://www.securitytracker.com/id/1030082

http://www.securitytracker.com/id/1030081

http://www.securitytracker.com/id/1030080

http://www.securitytracker.com/id/1030079

http://www.securitytracker.com/id/1030078

http://www.securitytracker.com/id/1030077

http://www.securitytracker.com/id/1030074

http://www.securitytracker.com/id/1030026

http://www.securityfocus.com/bid/66690

http://www.securityfocus.com/archive/1/534161/100/0/threaded

http://www.openssl.org/news/secadv_20140407.txt

http://www.kerio.com/support/kerio-control/release-history

http://www.innominate.com/data/downloads/manuals/mdm_1.5.2.1_Release_Notes.pdf

Details

Source: Mitre, NVD

Published: 2014-04-07

Updated: 2026-06-17

Named Vulnerability: HeartbleedNamed Vulnerability: HeartBleedKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High

EPSS

EPSS: 0.99999