statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.
We have discovered 435,656 live websites that are affected by CVE-2016-6309.
Product | ![]() |
Category | Web Server Extensions |
Vulnerable Domains | 435,656 live websites (64.98% of OpenSSL install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 11 versions ( 27.50% of all versions) |
![]() | 147,528 websites |
![]() | 40,012 websites |
![]() | 26,014 websites |
![]() | 25,701 websites |
![]() | 16,444 websites |
![]() | 14,973 websites |
![]() | 14,825 websites |
![]() | 12,153 websites |
![]() | 10,289 websites |
.com | 158,187 websites |
.de | 28,374 websites |
.net | 19,614 websites |
.nl | 18,988 websites |
.org | 16,522 websites |
.ru | 10,634 websites |
.jp | 10,293 websites |
.cz | 8,212 websites |
.it | 7,701 websites |
.com.br | 5,622 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.*************.se | ![]() | *** | |
****.com | ![]() | *** | |
********.*********.com | ![]() | *,*** | |
****.com | ![]() | *,*** | |
********.com | ![]() | *,*** | |
*******.com | ![]() | *,*** | |
*.******.***.***.br | ![]() | *,*** | |
*************.com | ![]() | *,*** | |
*.*****.***.***.br | ![]() | *,*** | |
****.**.com | ![]() | *,*** |
FAQ