CVE-2016-2180

The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted time-stamp file that is mishandled by the "openssl ts" command.


We have discovered 273,254 live websites that are affected by CVE-2016-2180.

Run a Free Instant Scan




Affected Software

Product  OpenSSL
Category Web Server Extensions
Vulnerable Domains273,254 live websites (52% of OpenSSL install base)
Vulnerable Versions
  • from 0 through 1.0.2
Vulnerable Versions Count11 versions ( 17% of all versions)



Details

  • Published - Aug 1, 2016
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2016-2180
United States68,275 websites



Japan22,295 websites
Germany18,860 websites
Korea, South13,532 websites
Netherlands12,916 websites
Singapore12,538 websites
Russia9,509 websites
France8,839 websites
China8,075 websites
Italy7,999 websites

Website Distribution by TLD

Number of websites using CVE-2016-2180
.com96,414 websites
.net12,446 websites
.de11,400 websites
.org11,169 websites
.nl9,793 websites
.jp8,189 websites
.ru7,902 websites
.it6,572 websites
.cz6,367 websites
.co.jp4,765 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-2180

Top websites that are affected by CVE-2016-2180. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.com United States*,***
********.com United States*,***
*.******.***.***.br Brazil*,***
*************.com GB*,***
*.*****.***.***.br Brazil*,***
****.**.com United States*,***
*****.org United States*,***
*****.com United States*,***
*********.io United States*,***
*******.in India*,***
See full domain list

FAQ

A total of 273,254 websites have been identified as vulnerable to CVE-2016-2180, based on global website indexing conducted by WebTechSurvey.
The OpenSSL is affected by the CVE-2016-2180 vulnerability.
OpenSSL versions up to and including 1.0.2 are vulnerable to CVE-2016-2180.

References