statem/statem.c in OpenSSL 1.1.0a does not consider memory-block movement after a realloc call, which allows remote attackers to cause a denial of service (use-after-free) or possibly execute arbitrary code via a crafted TLS session.
We have discovered 243,749 live websites that are affected by CVE-2016-6309.
| Product | |
| Category | Web Server Extensions |
| Vulnerable Domains | 243,749 live websites (50% of OpenSSL install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 13 versions ( 18% of all versions) |
| 57,971 websites | |
| 20,598 websites | |
| 16,773 websites | |
| 16,221 websites | |
| 12,468 websites | |
| 11,762 websites | |
| 8,400 websites | |
| 7,782 websites | |
| 7,246 websites |
| .com | 85,634 websites |
| .nl | 12,779 websites |
| .net | 11,496 websites |
| .de | 10,257 websites |
| .org | 9,612 websites |
| .cz | 9,526 websites |
| .jp | 7,390 websites |
| .ru | 7,100 websites |
| .it | 5,938 websites |
| .co.jp | 4,400 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.com | *,*** | ||
| ********.com | *,*** | ||
| *.******.***.***.br | *,*** | ||
| *.*****.***.***.br | *,*** | ||
| ****.**.com | *,*** | ||
| *****.org | *,*** | ||
| *****.com | *,*** | ||
| *******.in | *,*** | ||
| ********.biz | *,*** | ||
| ********.com | *,*** |