Direct Vulnerabilities

Known vulnerabilities in the openssl package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Integer Overflow or Wraparound

<1:3.5.5-1.amzn2023.0.5
  • H
Expired Pointer Dereference

<1:3.5.5-1.amzn2023.0.5
  • H
Improper Validation of Integrity Check Value

<1:3.5.5-1.amzn2023.0.5
  • H
Improper Handling of Length Parameter Inconsistency

<1:3.5.5-1.amzn2023.0.5
  • H
Incorrect Calculation of Buffer Size

<1:3.5.5-1.amzn2023.0.5
  • H
NULL Pointer Dereference

<1:3.5.5-1.amzn2023.0.5
  • H
Allocation of Resources Without Limits or Throttling

<1:3.5.5-1.amzn2023.0.5
  • H
NULL Pointer Dereference

<1:3.5.5-1.amzn2023.0.5
  • H
Improper Verification of Cryptographic Signature

<1:3.5.5-1.amzn2023.0.5
  • H
Improper Verification of Cryptographic Signature

<1:3.5.5-1.amzn2023.0.5
  • H
Improper Certificate Validation

<1:3.5.5-1.amzn2023.0.5
  • H
NULL Pointer Dereference

<1:3.5.5-1.amzn2023.0.5
  • H
Generation of Weak Initialization Vector (IV)

<1:3.5.5-1.amzn2023.0.5
  • H
Information Exposure

<1:3.5.5-1.amzn2023.0.5
  • H
Integer Overflow or Wraparound

<1:3.5.5-1.amzn2023.0.5
  • H
Access of Uninitialized Pointer

<1:3.5.5-1.amzn2023.0.4
  • H
NULL Pointer Dereference

<1:3.5.5-1.amzn2023.0.4
  • H
Improper Handling of Missing Special Element

<1:3.5.5-1.amzn2023.0.4
  • H
CVE-2026-28387

<1:3.5.5-1.amzn2023.0.4
  • H
NULL Pointer Dereference

<1:3.5.5-1.amzn2023.0.4
  • L
Missing Required Cryptographic Step

<1:3.5.5-1.amzn2023.0.3
  • H
Incorrect Calculation of Buffer Size

<1:3.2.2-1.amzn2023.0.5
  • H
Missing Required Cryptographic Step

<1:3.2.2-1.amzn2023.0.5
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<1:3.2.2-1.amzn2023.0.5
  • H
NULL Pointer Dereference

<1:3.2.2-1.amzn2023.0.5
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<1:3.2.2-1.amzn2023.0.5
  • H
Improper Validation of Specified Type of Input

<1:3.2.2-1.amzn2023.0.5
  • H
Out-of-bounds Write

<1:3.2.2-1.amzn2023.0.5
  • H
Allocation of Resources Without Limits or Throttling

<1:3.2.2-1.amzn2023.0.5
  • H
NULL Pointer Dereference

<1:3.2.2-1.amzn2023.0.5
  • H
Buffer Overflow

<1:3.2.2-1.amzn2023.0.4
  • M
Information Exposure

<1:3.2.2-1.amzn2023.0.2
  • M
Out-of-bounds Write

<1:3.2.2-1.amzn2023.0.2
  • M
Covert Timing Channel

<1:3.0.8-1.amzn2023.0.19
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

<1:3.0.8-1.amzn2023.0.15
  • M
Improper Certificate Validation

<1:3.0.8-1.amzn2023.0.16
  • M
CVE-2024-4603

<1:3.0.8-1.amzn2023.0.14
  • M
Information Exposure

<1:3.0.8-1.amzn2023.0.14
  • M
Use After Free

<1:3.0.8-1.amzn2023.0.14
  • M
Resource Exhaustion

<1:3.0.8-1.amzn2023.0.12
  • M
NULL Pointer Dereference

<1:3.0.8-1.amzn2023.0.11
  • M
Resource Exhaustion

<1:3.0.8-1.amzn2023.0.11
  • M
Missing Required Cryptographic Step

<1:3.0.8-1.amzn2023.0.10
  • H
Missing Required Cryptographic Step

<1:3.0.8-1.amzn2023.0.9
  • M
Excessive Iteration

<1:3.0.8-1.amzn2023.0.4
  • M
Resource Exhaustion

<1:3.0.8-1.amzn2023.0.4
  • M
Improper Authentication

<1:3.0.8-1.amzn2023.0.4
  • M
Resource Exhaustion

<1:3.0.8-1.amzn2023.0.3
  • M
Out-of-Bounds

<1:3.0.8-1.amzn2023.0.2
  • M
Improper Certificate Validation

<1:3.0.8-1.amzn2023.0.2
  • M
Improper Certificate Validation

<1:3.0.8-1.amzn2023.0.2
  • M
Resource Exhaustion

<1:3.0.8-1.amzn2023.0.2
  • H
NULL Pointer Dereference

<1:3.0.5-1.amzn2023.0.6
  • H
NULL Pointer Dereference

<1:3.0.5-1.amzn2023.0.6
  • H
Incorrect Type Conversion or Cast

<1:3.0.5-1.amzn2023.0.6
  • H
NULL Pointer Dereference

<1:3.0.5-1.amzn2023.0.6
  • H
Double Free

<1:3.0.5-1.amzn2023.0.6
  • H
Out-of-bounds Read

<1:3.0.5-1.amzn2023.0.6
  • H
Information Exposure

<1:3.0.5-1.amzn2023.0.6
  • H
Use After Free

<1:3.0.5-1.amzn2023.0.6
  • L
Double-Checked Locking

<1:3.0.5-1.amzn2023.0.7
  • M
Missing Required Cryptographic Step

<1:3.0.8-1.amzn2023.0.1
  • M
NULL Pointer Dereference

<1:3.0.8-1.amzn2023.0.1
  • H
Buffer Access with Incorrect Length Value

<1:3.0.5-1.amzn2023.0.4
  • H
Buffer Access with Incorrect Length Value

<1:3.0.5-1.amzn2023.0.4
  • H
Missing Required Cryptographic Step

<1:3.0.5-1.amzn2023.0.4
  • H
Arbitrary Command Injection

<1:3.0.5-1.amzn2023.0.4
  • H
Missing Release of Resource after Effective Lifetime

<1:3.0.5-1.amzn2023.0.4
  • H
Use of a Broken or Risky Cryptographic Algorithm

<1:3.0.5-1.amzn2023.0.4
  • H
Arbitrary Command Injection

<1:3.0.5-1.amzn2023.0.4
  • H
Improper Certificate Validation

<1:3.0.5-1.amzn2023.0.4
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1:3.0.5-1.amzn2023.0.4