openssl vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the openssl package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
CVE-2025-9231

<3.5.3-1ubuntu2
  • L
Out-of-bounds Write

<3.0.10-1ubuntu4
  • L
Out-of-bounds Read

<3.0.8-1ubuntu3
  • L
Improper Locking

<3.0.7-1ubuntu1
  • H
Buffer Overflow

<3.0.5-2ubuntu2
  • H
Buffer Overflow

<3.0.5-2ubuntu2
  • L
NULL Pointer Dereference

<3.0.5-2ubuntu2
  • L
Use of a Broken or Risky Cryptographic Algorithm

<3.0.2-0ubuntu2
  • L
Incomplete Cleanup

<3.0.2-0ubuntu2
  • M
Use of a Broken or Risky Cryptographic Algorithm

<3.0.5-2ubuntu1
  • M
OS Command Injection

<3.0.2-0ubuntu2
  • H
Buffer Overflow

<1.1.1l-1ubuntu1
  • H
NULL Pointer Dereference

<1.1.1j-1ubuntu3
  • L
Integer Overflow or Wraparound

<1.1.1j-1ubuntu1
  • L
Use of a Broken or Risky Cryptographic Algorithm

<1.1.1d-2ubuntu1
  • L
CVE-2024-4603

<3.2.2-1ubuntu1
  • L
CVE-2025-15468

<3.5.3-1ubuntu3
  • L
CVE-2025-15469

<3.5.3-1ubuntu3
  • L
CVE-2025-68160

<3.5.3-1ubuntu3
  • M
CVE-2025-15467

<3.5.3-1ubuntu3
  • M
CVE-2025-11187

<3.5.3-1ubuntu3
  • L
CVE-2025-69420

<3.5.3-1ubuntu3
  • L
CVE-2025-66199

<3.5.3-1ubuntu3
  • L
CVE-2025-69418

<3.5.3-1ubuntu3
  • L
CVE-2026-22795

<3.5.3-1ubuntu3
  • L
CVE-2026-22796

<3.5.3-1ubuntu3
  • L
CVE-2025-69419

<3.5.3-1ubuntu3
  • L
CVE-2025-69421

<3.5.3-1ubuntu3
  • M
Cryptographic Issues

<1.0.1f-1ubuntu9
  • M
CVE-2023-5363

<3.0.10-1ubuntu2.1
  • M
Double Free

<3.0.8-1ubuntu1
  • L
Improper Certificate Validation

<3.0.8-1ubuntu2
  • M
Allocation of Resources Without Limits or Throttling

<3.0.8-1ubuntu3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<3.0.2-0ubuntu1
  • L
Improper Certificate Validation

<3.0.8-1ubuntu2
  • M
Out-of-bounds Read

<1.1.1l-1ubuntu1
  • M
Information Exposure

<3.0.8-1ubuntu1
  • L
Improper Certificate Validation

<3.0.8-1ubuntu2
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<3.0.8-1ubuntu1
  • L
Improper Check for Unusual or Exceptional Conditions

<3.0.10-1ubuntu4
  • M
Use After Free

<3.0.8-1ubuntu1
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

<3.3.1-2ubuntu2
  • L
CVE-2024-0727

<3.0.10-1ubuntu4
  • L
CVE-2023-6237

<3.0.10-1ubuntu4
  • L
CVE-2024-13176

<3.4.1-1ubuntu1
  • L
CVE-2024-4741

<3.2.2-1ubuntu1
  • L
CVE-2024-5535

<3.2.2-1ubuntu2
  • L
CVE-2024-2511

<3.2.2-1ubuntu1
  • L
CVE-2025-9232

<3.5.3-1ubuntu2
  • M
CVE-2025-9230

<3.5.3-1ubuntu2