CVE-2014-0160

HIGH KEV NUCLEI

OpenSSL <1.0.1g - Info Disclosure

Title source: llm

Description

The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.

Exploits (83)

nomisec WORKING POC 2,522 stars
by FiloSottile · infoleak
https://github.com/FiloSottile/Heartbleed
nomisec SCANNER 574 stars
by musalbas · infoleak
https://github.com/musalbas/heartbleed-masstest
nomisec WORKING POC 451 stars
by titanous · infoleak
https://github.com/titanous/heartbleeder
nomisec WORKING POC 326 stars
by Lekensteyn · infoleak
https://github.com/Lekensteyn/pacemaker
nomisec WORKING POC 167 stars
by sensepost · infoleak
https://github.com/sensepost/heartbleed-poc
nomisec WORKING POC 97 stars
by einaros · infoleak
https://github.com/einaros/heartbleed-tools
nomisec WORKING POC 84 stars
by mpgn · infoleak
https://github.com/mpgn/heartbleed-PoC
nomisec WORKING POC 40 stars
by isgroup · infoleak
https://github.com/isgroup/openmagic
nomisec WRITEUP 19 stars
by jdauphant · poc
https://github.com/jdauphant/patch-openssl-CVE-2014-0160
nomisec WORKING POC 18 stars
by DisK0nn3cT · infoleak
https://github.com/DisK0nn3cT/MaltegoHeartbleed
nomisec WORKING POC 15 stars
by OffensivePython · infoleak
https://github.com/OffensivePython/HeartLeak
nomisec WORKING POC 14 stars
by hmlio · poc
https://github.com/hmlio/vaas-cve-2014-0160
nomisec SCANNER 11 stars
by hybridus · infoleak
https://github.com/hybridus/heartbleedscanner
nomisec WORKING POC 8 stars
by 0x90 · infoleak
https://github.com/0x90/CVE-2014-0160
nomisec WORKING POC 7 stars
by DominikTo · poc
https://github.com/DominikTo/bleed
nomisec WORKING POC 6 stars
by 0xinf0 · poc
https://github.com/0xinf0/bleeding_onions
nomisec WORKING POC 5 stars
by hreese · infoleak
https://github.com/hreese/heartbleed-dtls
nomisec SCANNER 5 stars
by anthophilee · poc
https://github.com/anthophilee/A2SV--SSL-VUL-Scan
nomisec WORKING POC 5 stars
by undacmic · infoleak
https://github.com/undacmic/heartbleed-proof-of-concept
nomisec WORKING POC 4 stars
by yryz · infoleak
https://github.com/yryz/heartbleed.js
nomisec WRITEUP 3 stars
by ingochris · poc
https://github.com/ingochris/heartpatch.us
nomisec SCANNER 3 stars
by mozilla-services · poc
https://github.com/mozilla-services/Heartbleed
nomisec SCANNER 2 stars
by amerine · infoleak
https://github.com/amerine/coronary
nomisec WRITEUP 2 stars
by zouguangxian · infoleak
https://github.com/zouguangxian/heartbleed
nomisec WORKING POC 2 stars
by indrajeetmp11 · infoleak
https://github.com/indrajeetmp11/Heartbleed-PoC-Exploit-Script
nomisec SCANNER 2 stars
by cyphar · infoleak
https://github.com/cyphar/heartthreader
nomisec WORKING POC 2 stars
by waqasjamal-zz · poc
https://github.com/waqasjamal-zz/HeartBleed-Vulnerability-Checker
nomisec SCANNER 2 stars
by pblittle · poc
https://github.com/pblittle/aws-suture
nomisec WRITEUP 2 stars
by GardeniaWhite · poc
https://github.com/GardeniaWhite/fuzzing
nomisec WORKING POC 2 stars
by GuillermoEscobero · infoleak
https://github.com/GuillermoEscobero/heartbleed
github WORKING POC 1 stars
by vadimgggg · pythonpoc
https://github.com/vadimgggg/CVE-PoC/tree/main/CVE-2014-0160
nomisec WORKING POC 1 stars
by belmind · infoleak
https://github.com/belmind/heartbleed
nomisec WORKING POC 1 stars
by Saymeis · poc
https://github.com/Saymeis/HeartBleed
nomisec SCANNER 1 stars
by proactiveRISK · poc
https://github.com/proactiveRISK/heartbleed-extention
nomisec WORKING POC 1 stars
by cheese-hub · poc
https://github.com/cheese-hub/heartbleed
nomisec STUB 1 stars
by Xyl2k · poc
https://github.com/Xyl2k/CVE-2014-0160-Chrome-Plugin
nomisec SCANNER 1 stars
by vortextube · poc
https://github.com/vortextube/ssl_scanner
nomisec WORKING POC 1 stars
by xlucas · infoleak
https://github.com/xlucas/heartbleed
nomisec WORKING POC 1 stars
by sammyfung · poc
https://github.com/sammyfung/openssl-heartbleed-fix
nomisec SCANNER
by obayesshelton · poc
https://github.com/obayesshelton/CVE-2014-0160-Scanner
nomisec SCANNER
by marstornado · remote
https://github.com/marstornado/cve-2014-0160-Yunfeng-Jiang
github WRITEUP
by OscarYR · poc
https://github.com/OscarYR/CVE_Reproduction/tree/main/Heartbleed/CVE-2014-0160.md
nomisec SCANNER
by cbk914 · infoleak
https://github.com/cbk914/heartbleed-checker
nomisec WORKING POC
by timsonner · infoleak
https://github.com/timsonner/cve-2014-0160-heartbleed
nomisec WORKING POC
by yashfren · infoleak
https://github.com/yashfren/CVE-2014-0160-HeartBleed
nomisec WORKING POC
by Shayhha · infoleak
https://github.com/Shayhha/HeartbleedAttack
nomisec WORKING POC
by pierceoneill · infoleak
https://github.com/pierceoneill/bleeding-heart
nomisec WRITEUP
by zaryouhashraf · poc
https://github.com/zaryouhashraf/CVE-2014-0160
nomisec WRITEUP
by 0xAshwesker · poc
https://github.com/0xAshwesker/CVE-2014-0160
nomisec WORKING POC
by 22imer · poc
https://github.com/22imer/CVE-2014-0160
nomisec WORKING POC
by SimoesCTT · poc
https://github.com/SimoesCTT/CTT-HEARTBLEED-Temporal-Resonance-Memory-Leak-Exploit-Heartbleed-CVE-2014-0160
nomisec WORKING POC
by rouze-d · poc
https://github.com/rouze-d/heartbleed
nomisec WORKING POC
by WildfootW · remote
https://github.com/WildfootW/CVE-2014-0160_OpenSSL_1.0.1f_Heartbleed
nomisec WRITEUP
by cved-sources · poc
https://github.com/cved-sources/cve-2014-0160
nomisec WORKING POC
by takeshixx · infoleak
https://github.com/takeshixx/ssl-heartbleed.nse
nomisec SCANNER
by siddolo · poc
https://github.com/siddolo/knockbleed
nomisec WORKING POC
by a0726h77 · poc
https://github.com/a0726h77/heartbleed-test
nomisec WORKING POC
by GeeksXtreme · poc
https://github.com/GeeksXtreme/ssl-heartbleed.nse
nomisec WORKING POC
by froyo75 · poc
https://github.com/froyo75/Heartbleed_Dockerfile_with_Nginx
nomisec SCANNER
by roganartu · poc
https://github.com/roganartu/heartbleedchecker-chrome
nomisec WORKING POC
by MrE-Fog · poc
https://github.com/MrE-Fog/CVE-2014-0160-Chrome-Plugin
nomisec WORKING POC
by h3x0v3rl0rd · poc
https://github.com/h3x0v3rl0rd/CVE-2014-0160_Heartbleed
nomisec WORKING POC
by ThanHuuTuan · poc
https://github.com/ThanHuuTuan/Heartexploit
nomisec WORKING POC
by idkqh7 · poc
https://github.com/idkqh7/heatbleeding
nomisec SCANNER
by iSCInc · poc
https://github.com/iSCInc/heartbleed
nomisec WRITEUP
by ArtemCyberLab · poc
https://github.com/ArtemCyberLab/Project-Field-Analysis-and-Memory-Leak-Demonstration
nomisec WORKING POC
by artofscripting-zz · remote
https://github.com/artofscripting-zz/cmty-ssl-heartbleed-CVE-2014-0160-HTTP-HTTPS
nomisec WORKING POC
by tomdevman · poc
https://github.com/tomdevman/heartbleed-bug
nomisec WORKING POC
by caiqiqi · remote
https://github.com/caiqiqi/OpenSSL-HeartBleed-CVE-2014-0160-PoC
vulncheck_xdb WORKING POC
local
https://gitlab.com/ret2eax/pacemaker
exploitdb WORKING POC VERIFIED
by Jared Stafford · pythonremotemultiple
https://www.exploit-db.com/exploits/32745
vulncheck_xdb WORKING POC
remote
https://github.com/threat9/routersploit
metasploit WORKING POC
by Neel Mehta, Riku, Antti, Matti, hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/server/openssl_heartbeat_client_memory.rb
exploitdb WORKING POC VERIFIED
by Fitzl Csaba · pythonremotemultiple
https://www.exploit-db.com/exploits/32764
metasploit WORKING POC
by Neel Mehta, Riku, Antti, Matti · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/ssl/openssl_heartbleed.rb
exploitdb WORKING POC
cremotemultiple
https://www.exploit-db.com/exploits/32791
exploitdb WORKING POC
cremotemultiple
https://www.exploit-db.com/exploits/32998

Nuclei Templates (1)

OpenSSL Heartbleed Vulnerability
HIGHVERIFIEDby pussycat0x

References (129)

... and 109 more

Scores

CVSS v3 7.5
EPSS 0.9446
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploitation Intel

CISA KEV 2022-05-04
VulnCheck KEV 2016-09-29
InTheWild.io 2014-04-18
ENISA EUVD EUVD-2014-0217

Classification

CWE
CWE-125
Status draft

Affected Products (47)

openssl/openssl < 1.0.1g
filezilla-project/filezilla_server < 0.9.44
siemens/application_processing_engine_firmware
siemens/cp_1543-1_firmware
siemens/simatic_s7-1500_firmware
siemens/simatic_s7-1500t_firmware
siemens/elan-8.2 < 8.3.3
siemens/wincc_open_architecture
intellian/v100_firmware
intellian/v100_firmware
intellian/v100_firmware
intellian/v60_firmware
intellian/v60_firmware
mitel/micollab
mitel/micollab
... and 32 more

Timeline

Published Apr 07, 2014
KEV Added May 04, 2022
Tracked Since Feb 18, 2026