CVE-2016-6309

statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.


We have discovered 435,656 live websites that are affected by CVE-2016-6309.

Test my site




Affected Software

Product  OpenSSL
Category Web Server Extensions
Vulnerable Domains435,656 live websites (64.98% of OpenSSL install base)
Vulnerable Versions
  • from 0 before 1.1
Vulnerable Versions Count11 versions ( 27.50% of all versions)



Details

  • Published - Sep 27, 2016
  • Updated - Aug 6, 2024

CVE-2016-6309 usage by Country

United States147,528 websites



Germany40,012 websites
Japan26,014 websites
Netherlands25,701 websites
Korea, South16,444 websites
Singapore14,973 websites
France14,825 websites
Russia12,153 websites
China10,289 websites

CVE-2016-6309 usage by TLD

.com158,187 websites
.de28,374 websites
.net19,614 websites
.nl18,988 websites
.org16,522 websites
.ru10,634 websites
.jp10,293 websites
.cz8,212 websites
.it7,701 websites
.com.br5,622 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2016-6309

Top websites that are affected by CVE-2016-6309. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.*************.se United States***
****.com United States***
********.*********.com Singapore*,***
****.com United States*,***
********.com United States*,***
*******.com United States*,***
*.******.***.***.br Brazil*,***
*************.com GB*,***
*.*****.***.***.br Brazil*,***
****.**.com United States*,***
See full domain list

FAQ

A total of 435,656 websites have been identified as vulnerable to CVE-2016-6309, discovered through global website indexing conducted by WebTechSurvey.
OpenSSL is susceptible to CVE-2016-6309 vulnerability.
OpenSSL versions before 1.1 are vulnerable to CVE-2016-6309.
Version 1.1 of OpenSSL addresses the CVE-2016-6309 security vulnerability.

References