CVE-2016-2177

OpenSSL through 1.0.2h incorrectly uses pointer arithmetic for heap-buffer boundary checks, which might allow remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact by leveraging unexpected malloc behavior, related to s3_srvr.c, ssl_sess.c, and t1_lib.c.


We have discovered 251,696 live websites that are affected by CVE-2016-2177.

Run a Free Instant Scan




Affected Software

Product  OpenSSL
Category Web Server Extensions
Vulnerable Domains251,696 live websites (50% of OpenSSL install base)
Vulnerable Versions
  • from 0 through 1.0.2
Vulnerable Versions Count12 versions ( 16% of all versions)



Details

  • Published - Jun 20, 2016
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2016-2177
United States61,365 websites



Japan21,018 websites
Germany17,148 websites
Netherlands15,817 websites
Korea, South12,767 websites
Czech Republic10,386 websites
Russia8,592 websites
France7,854 websites
Italy7,413 websites

Website Distribution by TLD

Number of websites using CVE-2016-2177
.com88,086 websites
.nl12,618 websites
.net11,618 websites
.de10,438 websites
.org10,164 websites
.cz8,317 websites
.jp7,599 websites
.ru7,247 websites
.it6,077 websites
.co.jp4,497 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-2177

Top websites that are affected by CVE-2016-2177. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.com United States*,***
********.com United States*,***
*.******.***.***.br Brazil*,***
*.*****.***.***.br Brazil*,***
****.**.com United States*,***
*****.org United States*,***
*****.com United States*,***
*******.in United States*,***
********.biz Japan*,***
********.com United States*,***
See full domain list

FAQ

A total of 251,696 websites have been identified as vulnerable to CVE-2016-2177, based on global website indexing conducted by WebTechSurvey.
The OpenSSL is affected by the CVE-2016-2177 vulnerability.
OpenSSL versions up to and including 1.0.2 are vulnerable to CVE-2016-2177.

References